Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 8 Apr 2014 13:42:10 -0400
From:      Chris Nehren <cnehren+freebsd-security@pobox.com>
To:        freebsd-security@freebsd.org
Subject:   FreeBSD's heartbleed response
Message-ID:  <20140408174210.GA5433@behemoth>

next in thread | raw e-mail | index | archive | help

--IJpNTDwzlM2Ie8A6
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

First, please let me say that I understand that FreeBSD is a
volunteer project.  I know that most everyone is using donated
time and donated hardware.  You'll find some old email addresses
of mine in the ports collection, in fact, and it's in the spirit
of volunteering that I write today.

The Heartbleed vulnerability is probably the highest priority,
farthest-reaching vulnerability I've ever seen.  Yet nearly a day
later, FreeBSD remains unpatched.  There are many worried
sysadmins and other users in #freebsd and elsewhere wondering
what's going on and when their systems will be patched.  So far
all we have is an unofficial gist on github and some discussion
here (which most users don't see) with no further information.
More transparency is needed.

Given the above, I come with a request to help: how can the
userbase at large help with getting these sorts of fixes out more
quickly?  I and others have hardware and time we'd be glad to
donate if it would help resolve these sorts of critical issues
more quickly.

I'm sorry if I sound impatient.  I want to help, but don't know
how, so I'm asking here.=20

--=20
Chris Nehren

--IJpNTDwzlM2Ie8A6
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (FreeBSD)

iQJdBAABAgBHBQJTRDTyQBSAAAAAABUAInBrYS1hZGRyZXNzQGdudXBnLm9yZ2Nu
ZWhyZW4rZnJlZWJzZC1zZWN1cml0eUBwb2JveC5jb20ACgkQHo59aFf/oVPwBQ/+
KNZ9XVIq2Yon3T/jHMM+nKJAsaztrkv1uWTj5RNl2a+qUJRkfPoS8bFvF12WTO9B
zqlr1faxXPsm6uZ5qFyNYZCzQJJq3QpQpVhK3lgqLLUukJRaVmwPleI0OstkrYmX
ZNfdvghFtDM5eYmXaJpbrNFoEF8Akh9jtKXti+LIHdL7A2FIOKJIoEcA5Yo5F4p4
iTW/2qAsj0xWHtTmAwcwZCp5d+b2nsPODUlXPAFvtsb5A6oMx/zcN3gHDgIAfvD6
4zba1YDPKfptzgJQOPxHBC6SI9YVb8H3vS25SAGZF/i0REBfuUXMnkaMdTPWYhoK
RazFWBSkBW+/YnjP9qUxZ//uJxiZcUtA89c3x9SxcgjKiwD7uwLdVFxgUfcEma4b
LLvtGGep8lPZIpEoM7tFe5QeW0dasgAuRIttYdRbkIq/qs837u9FWPkovEGOAejY
fyn10ggqkSZxQnpjKLpuWvMx19JjGqLxlKJQPOeCiKBAOhpq5xX1NTKGM+ayUdwu
7e1zjvKBH1nGETGA+WgbHN3geBBDEMgFzVXUpFqHsZwOT/4aieMK2YhsNycdNTBn
Olka6hSnnSI+QpFG2sqfPyjivKiFus4cmroEDIgTVdYKfcAyJXwz8k19eWiVYHYs
M4GK3UvNYYqR5CWZ3u93qW2bzwYuPU23wiIbWfVSa4A=
=etNK
-----END PGP SIGNATURE-----

--IJpNTDwzlM2Ie8A6--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20140408174210.GA5433>