|
Message-Id: <F47CFA85-FA37-4287-9921-C056C0CA8FF0@shub-internet.org>
Date: Sat, 25 Jul 2015 19:41:08 -0500
From: Brad Knowles <brad@...b-internet.org>
To: oss-security@...ts.openwall.com
Cc: Brad Knowles <brad@...b-internet.org>
Subject: Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser
On Jul 25, 2015, at 4:55 PM, Dave Horsfall <dave@...sfall.org> wrote:
> What would be a reasonable interval (for some definition of "reasonable")
> in that case? 24 hours? 48 hours? 0 hours?
Any value you choose will be wrong, because there will always be people on both sides of that argument who are violently opposed to any value longer or shorter than what they think is appropriate. Consensus is not only impossible, but these people will actively work to prohibit any possible consensus.
Thus begins the flame wars.
--
Brad Knowles <brad@...b-internet.org>
LinkedIn Profile: <http://tinyurl.com/y8kpxu>
Download attachment "signature.asc" of type "application/pgp-signature" (833 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.