Linked by Mark Tolliver on Thu 13th Sep 2007 08:14 UTC
Thread beginning with comment 271092
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.
RE[3]: Response times
by dylansmrjones on Thu 13th Sep 2007 17:09
in reply to "RE[2]: Response times"
Who said anything about OpenBSD
sappyvcv attacked a specific security policiy of open source projects, and this specific security policy happens to be the security policy of OpenBSD.
proprietary vendors not only have to worry about their own products but products that rely on their own products;
So open source projects sponsored by Novell, Redhat, IBM etc. don't have to worry about the projects depending on them?
they have to ensure that in the process of fixing up a flaw, that in the same process they don't end up breaking compatibility with something that relies on it.
And isn't this also true for open source projects? Or do you claim that no products are based on open source?
Hang on, did you actually read *ALL* the post; did you miss the second paragraph where I actually expanded saying that it could be avoided if the proprietary vendors communicated better each other. Communicated better just as there is good communication between the various open source projects.
I'm not trying to be mean, but do you actually read *ALL* the post before hitting the reply button? honestly - tell me, because I am confused as heck trying to understand how the hell you came to the conclusions that you did.






Member since:
2005-07-06
Who said anything about OpenBSD; proprietary vendors not only have to worry about their own products but products that rely on their own products; they have to ensure that in the process of fixing up a flaw, that in the same process they don't end up breaking compatibility with something that relies on it.
With that being said, however, I think the issue shouldn't necessarily be one of 'excusing' delays but instead asking why these companies haven't setup better communication with their partners so that rather than compromising on security fixes for the sake of compatibility, their partners are the first to know about the fix plus what has been fixed so that partners can issue updates for their respective tools at the same time updates are released for the main programme in question.