Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 05 May 2016 18:25:24 +0200
From:      "Julian H. Stacey" <jhs@berklix.com>
To:        freebsd-security@freebsd.org
Subject:   Re: Batching errata & advisories in heaps degrades security.
Message-ID:  <201605051625.u45GPODc084944@fire.js.berklix.net>
In-Reply-To: Your message "Thu, 05 May 2016 11:07:56 -0400." <alpine.GSO.1.10.1605051104570.26829@multics.mit.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
Benjamin Kaduk wrote:

> As a member of the security team for two projects (not FreeBSD's, though),
> I can say that it is a lot of behind-the-scenes work to put out
> advisories,

Of course.

> and batching them reduces the unit cost of any given one.

If so, their issue, not ours.  Our concern is FreeBSD.


> the
> contents of the errata notices have been public for quite some time

URLs ? If info was complete early, delaying those announcement
degraded security of recipients. Batching also swamps recipients.

Julian
--
Julian Stacey, BSD Linux Unix Sys Eng Consultant Munich http://berklix.eu/jhs/
 Mail plain text,  No quoted-printable, HTML, base64, MS.doc.
 Prefix old lines '> '  Reply below old, like play script.  Break lines by 80.
 Brexit: Meeting +UK blocks votes of Brits in EU  http://www.berklix.eu/brexit/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201605051625.u45GPODc084944>