oss-sec mailing list archives
Re: Qualys Security Advisory - The Stack Clash
From: Josh Bressers <josh () bress net>
Date: Wed, 21 Jun 2017 07:35:34 -0500
On Mon, Jun 19, 2017 at 3:39 PM, Solar Designer <solar () openwall com> wrote:
That said, we owe apologies to the community for violating the published distros list policy regarding the maximum embargo duration. Personally and as distros list admin, I do apologize for letting this happen. I think we shouldn't have let it happen.
I suspect the extended embargo was exactly correct in this instance. Having a policy you follow no matter what isn't ideal either (in fact it's probably dangerous). We've all been through a lot of embargoes, two weeks is more than acceptable for most of them, it's a very good thing to have a forcing function when needed. This one was special, nobody can deny that. It was big, complex, and amazing. It ticked all the boxes. It affected a substantial portion of the Internet. Had a name. Is a very old bug. Was very serious. Had a great advisory and organization behind it. Yet nobody flipped out. It was unexciting. I suspect it was all so smooth because on Monday because everyone was ready, everyone knew what was going on. There was no rushing, nothing was on fire. There was time to develop patches properly. Everyone had their story straight. It's quite likely if you force a release in two weeks because that's the rule, someone not ready would create a story where one shouldn't exist. I applaud everyone involved. I'm sure there were issues, but I doubt such a large effort could have gone better. Rules such as this exist to guide us, don't let them constrain us. -- JB
Current thread:
- Re: Qualys Security Advisory - The Stack Clash, (continued)
- Re: Qualys Security Advisory - The Stack Clash kseifried () redhat com (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Daniel Micay (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Marcus Meissner (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 20)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash nospam (Jun 21)
- Re: Re: Qualys Security Advisory - The Stack Clash Franz Pletz (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 25)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 28)
- Re: Qualys Security Advisory - The Stack Clash Daniel Micay (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash kseifried () redhat com (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Josh Bressers (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Stuart Henderson (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash kseifried () redhat com (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Jeff Law (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Daniel Micay (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Florian Weimer (Jun 22)
- Re: Qualys Security Advisory - The Stack Clash Brad Spengler (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 21)