Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: [8lgm]-Advisory-14.UNIX.SCO-prwarn.12-Nov-1994
From: casper () fwi uva nl (Casper Dik)
Date: Tue, 29 Nov 1994 10:17:47 +0100



Gene Spafford writes:
[...deleted...]
I'm also not trying to reopen the debate about full vs. partial vs. no
disclosure.  I'd like to see some hard evidence for things, though,
and *not* debate.  Even my experience has been anecdotal (but I
believe that it is more representative of the true user community than
these lists are).  Statements to the effect that "policy X produces
patches faster than policy Y" should be backed up by testable data.
Otherwise, they fall in the category of faith healing, diet aids, and
sightings of Elvis -- the observer may believe it is true, but there
is no controlled way to demonstrate it to skeptical observers in a
general setting.

Stating the obvious here, but we seem to be in the experiment now.

With 8lgm in the past, going with full disclosure.  One needs
to recall how quickly sun/ibm came up with patches for published
holes.

Change that in: "how quickly Sun came with not-working patches"
Note too that the patch that finally fixed the /var/spool/mail
race conditions appeared months after the last 8lgm advisory.


Casper



  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]