[Dailydave] [Full-disclosure] Linux's unofficial security-through-coverup policy

Thomas Ptacek tqbf at matasano.com
Fri Jul 18 11:49:58 EDT 2008


>  And Linus's point is that many of those regressions matter *more* than most
>  security bugs, because they can totally hose your system too - corrupt
>  filesystems, cause system hangs and lockups, poor performance, and who knows
>  what else.

And this is where Linus lapses into crazy talk, because data
corruption bugs are far less important than vulnerabilities that can
compromise my mom's credit card numbers and bank accounts. Bugs don't
have adversaries. Vulnerabilities do.

But I feel Linus' pain.

-- 
---
Thomas H. Ptacek // matasano security
read us on the web: http://www.matasano.com/log


More information about the Dailydave mailing list