Re: BIND update?



Wesley Shields writes:

Malware authors create exploits based on information they gleaned by
reverse

(legitimate businesses). I'm also not sure how this applies since the
project is open source - the fix is published at the time of the patch,

My implicit (sorry about that) point was that if closed source software has
no obscurity, there's no way open source software can have any. So we should
not pretend that there is any, nor that it can help. The best course is to
provide users full information about the risks they face and to respond with
timely and correct fixes to those issues that introduce unnecessary risk.

In this case, the BIND bug is already patched and publicly available anyway.

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Questions about Bootcamp and Parallels
    ... installing them. ... And the fix *is* mentioned in the comments on that very same web page. ... Open source development typically moves faster than commercial ware, ... Is it your contention that open source software is written by ...
    (comp.sys.mac.system)
  • Re: Open_Source
    ... With closed source both are more difficult. ... it's easier to discover vulnerabilities through reverse ... The purely technical difference provided by open source software when it ...
    (freebsd-questions)
  • Jambo Open Office...
    ... Swahili Free and Open Source Software. ... APC Forum is a meeting place for the APC community - people and ...
    (comp.os.linux.announce)
  • Re: the safety of gnupg
    ... the mathematics of how to do PGP would seem to be considered as ... One of the points raised was: "What's the point in open source if it ... Open source software has a change of being ... ability to check the source code myself. ...
    (Fedora)
  • Re: Ruby Editor
    ... but don't force your license on others. ... for open source software isn't really entirely accurate (or, conversely, ... the implication that there *is* necessarily support for closed source ...
    (comp.lang.ruby)