Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 9:13 AM, Simon Oosthoek wrote:

>>> I specifically purchased CS3.0 for this exact reason - so I
>>> wouldn't have to
>>> worry about building stuff from sources each time there was an  
>>> update.
>>>
>>
>> You bought CS3 so that you would get the latest version of package
>> xyz while everyone else was getting a patched version?  I feel sorry
>> for you, Bob.  Either someone suckered you or you just plain old
>> misunderstood what the extra life support in CS3 was all about (which
>> is odd because nowhere can I see CS3 or CD3 being advertised as
>> getting the latest versions of stuff while other people get patches).
>>
>>
>
> Perhaps I'm expecting too much (as I'm sure you'll be happy to  
> confirm), but
> I consider support to be sufficient to keep my system unbroken and  
> secure
> during the supported period. If the nature of the software, which is
> determined outside the control of Mandriva, is that newer versions are
> required to be unbroken and secure, that implies that Mandriva should
> provide these newer versions during the support period. Of course,  
> that's
> just my personal opinion...

The package is patched.  What's broken and insecure?  The security  
hole is closed.  clamav works.  I fail to see your point.

> BTW Vincent, I don't think your employer gets happy from the way  
> you treat
> paying customers... As a relative freeloader (I'm only a silver  
> club member)
> I know to silently put up with your short fuse, but it's just not a  
> pretty
> sight to see you dis a real customer...

Ummm.. I don't have a short fuse.  Ask my daughter... I'm  
exceptionally patient.  =)  Unfortunately, my problem isn't that I  
have a short fuse, it's that I call things as I see them without  
sugar coating it (ask my wife... this is definitely one "fault" that  
she probably could do without).  I wasn't "dissing" Bob.  I was  
making an observation.  Someone either did sucker him into thinking  
that he would get new versions of software with CS, or he  
misunderstood what the extended support lifetime is.  That's not  
"dissing" him.  That's simply saying that someone told him something  
that wasn't true, or he just didn't understand something that should  
have been clear enough.  *I* haven't seen any thing that even  
remotely suggests software will be updated to the latest version in CS.

And my employer is quite happy with me, thankyouverymuch.  In fact,  
sitting on this list and even replying to these mails is not part of  
my job and I am not required to be here at all, so, having said, that  
I'm going above and beyond the call of duty to even read this list,  
nevermind respond on it.  My employer appreciates that singular  
dedication; it's unfortunate you do not.

> And about the other distro's, there never a need to follow a bad  
> example. If
> you can think up a better solution, that can help you stand out  
> from the
> others, it's not a bad thing to stand out positively in a  crowd!

Give me the same resources the other distros have and I guarantee you  
we will stand out from the crowd.  Given the lesser resources at my  
disposal compared to most other distros, I think we're doing a damn  
fantastic job.  If I was on par with, say, the SUSE team, what we  
could accomplish would literally blow your mind.  =)

Until then, I have to keep a tight reign on resource expenditure to  
make sure the best job possible can be accomplished with what I have  
at my disposal and that is a fine line to walk to keep everyone as  
happy as possible.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.