Re: [pgsql-advocacy] MySQL worm attacks Windows servers

From: Greg Stark <gsstark(at)mit(dot)edu>
To: pgsql-general(at)postgresql(dot)org
Subject: Re: [pgsql-advocacy] MySQL worm attacks Windows servers
Date: 2005-02-06 21:31:49
Message-ID: 87wttliddm.fsf@stark.xeocode.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-advocacy pgsql-general pgsql-www


Jan Wieck <JanWieck(at)Yahoo(dot)com> writes:

> No, Peter.
>
> Posting a vulnerability on a public mailing list "before" there is a known fix
> for it means that you put everyone who has that vulnerability into jeopardy.
> Vulnerabilities are a special breed of bugs and need to be exterminated a
> little different.

Many people disagree with this. Posting the vulnerability isn't what puts
people into jeopardy, the presence of the vulnerability puts people in
jeopardy. Posting it at least allows people to disable the feature or close
off access. Or at least monitor for possible intrusions. Not posting it leaves
people in jeopardy and in the dark about it.

If you think you're the first one to find the vulnerability you're probably
wrong. Often malicious hackers who search for vulnerabilities find them and
keep them secret long before they're reported.

How would you feel if your system was compromised and then you found out later
that it was a known security hole in a feature you had no need for and the
vulnerability had been kept secret?

This is really the wrong place to have such a debate. This is a long-standing
debate and one that you should at just recognize exists. Don't present one
side as dogma.

--
greg

In response to

Responses

Browse pgsql-advocacy by date

  From Date Subject
Next Message Francois Suter 2005-02-07 08:31:14 Re: [pgsql-advocacy] Solutions Linux 2005 Paris : debriefing
Previous Message J. Greenlees 2005-02-06 16:56:49 Re: [GENERAL] MySQL worm attacks Windows servers

Browse pgsql-general by date

  From Date Subject
Next Message Jim Morcombe 2005-02-07 08:07:41 Can't build libpq test example
Previous Message Christopher Browne 2005-02-06 18:38:12 Re: Update command too slow

Browse pgsql-www by date

  From Date Subject
Next Message Justin Clift 2005-02-07 14:04:13 Techdocs "guides" wrong version
Previous Message Marc G. Fournier 2005-02-06 19:28:39 svr2 on borg live