[Full-disclosure] Comments on: Browser patches yearn to be free



by n3td3v September 27, 2008 5:11 AM PDT

Once a month stops people getting confused, and allows people to
organize patch management better.

You know when the patches are due to be released, so you don't miss
any and get hacked when a hacker reverse engineers the patch.

If you just release patches on random days, folks might get caught off
guard and miss patching as quickly as they might want.

Also, third party patches are the most danergous patches, so its
better to know when the genuine patch is coming out.

I never agreed with the whole ZERT thing, its just encouraging the bad
guys to release third party patches which could be malware pretending
to be a patch.

Never accept third party patches, even if they are from ZERT, it sets
a bad precedence.

http://news.cnet.com/8601-13554_3-10052873.html?communityId=2032&targetCommunityId=2032&blogId=33&tag=mncol;tback#5009236

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • 9_Recommended error codes (specifically return code 5)
    ... * "return code 2" indicates patches are already installed. ... * "return code 25" means a patches requires another patch that is not yet installed. ... With or without using the save option, the patch installation process ... Installing 114008-01... ...
    (SunManagers)
  • Re: This is [Re:] How to improve the quality of the kernel[?].
    ... The -mm kernel already implements what your proposed PTS would do. ... If patch have no TS ID, ... Thus i can apply for example lguest patches and implement and test new ... How many open source projects use Bugzilla and how many use the Debian BTS? ...
    (Linux-Kernel)
  • Re: ATTACK of the WEEK-fentanyl patches
    ... FDA warns of deaths from fentanyl patch ... Some of the deaths came after doctors prescribed the patches to the ... The drug is only for chronic pain in people used to narcotics, ...
    (alt.support.chronic-pain)
  • Tru64 and OpenVMS patch announcements change after next month
    ... distribution of various patches ... OpenVMS systems with DCE and/or RPC installed. ... Update on OpenVMS and Tru64 UNIX Patches in HP ITRC ... Tru64 patch server will soon be shutdown. ...
    (Bugtraq)
  • Re: Conflicting info between the global Security Bulletin and some SPi Security Bulletin
    ... The MS02-050 is explicitly listed as included in SP4 AND in Rollup 1 ... I think the correct answer is that it depends on the era of the patch. ... installers do not always use such ... patches later than the end of 2002 are ...
    (microsoft.public.win2000.security)