OpenBSD and the latest OpenSSL bugs
OpenBSD and the latest OpenSSL bugs
Posted Jun 14, 2014 22:33 UTC (Sat) by spender (guest, #23067)In reply to: OpenBSD and the latest OpenSSL bugs by viro
Parent article: OpenBSD and the latest OpenSSL bugs
I'm not a fan of embargoes either, so I don't subscribe to such lists. That said, we generally can respond quicker than a distro and are rarely ever affected by public exploits (unlike upstream).
So your arguments are a little stale, and I don't much care for your alternative of "just fixing the bug" with your not-so-cute one-liner commit messages, sometimes introducing new bugs in the process (revealed by subsequent one-liner commit messages).
Seems to me like you want a distraction from the massive problems with upstream's own security handling, as if it's the existence of these cherry-picked security "researchers" from years ago that are continuing to prevent you today from taking security seriously.
A researcher who reports to security@kernel.org today will end up seeing their issue fixed without any mention of security with one of Linus' signature commit messages. It's getting a little old and I'm surprised people are still buying your stale excuses.
-Brad