Re: [Security-Discuss] Re: [Security Announce] MDKSA-2005:113 - Updated clamav packages fix vulnerability

Vincent Danen <vdanen-4qZELD6FgxhWk0Htik3J/[email protected]> Tue, 12 Jul 2005 11:49:21 -0600
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 12-Jul-05, at 11:26 AM, Simon Oosthoek wrote:

>>> Perhaps I'm expecting too much (as I'm sure you'll be happy to
>>> confirm), but
>>> I consider support to be sufficient to keep my system unbroken and
>>> secure
>>> during the supported period. If the nature of the software, which is
>>> determined outside the control of Mandriva, is that newer  
>>> versions are
>>> required to be unbroken and secure, that implies that Mandriva  
>>> should
>>> provide these newer versions during the support period. Of course,
>>> that's
>>> just my personal opinion...
>>>
>>
>> The package is patched.  What's broken and insecure?  The security
>> hole is closed.  clamav works.  I fail to see your point.
>>
>
> As Oden pointed out, clamav 0.81 complains about lack of  
> functionality due
> to being too old. To the average sysadmin, that would scream  
> "broken". Now
> you could take the message away, or you could try to fix the real  
> problem,
> but then we aparently get into resource problems...

Yes, but that's a warning, nothing more.  I can update the signatures  
with freshclam just fine.  This was verified in testing.  I  
understand it's not as sexy as having the latest version, but it  
works and the hole is patched.  At the end of the day, that's all  
that is really required.  That is the base minimum requirement and of  
course the people who want the latest version will say it's enough  
while the people that have to do the QA and regression testing on a  
new version will say patching is enough.  I doubt there will be  
agreement between the two "camps".

>>> BTW Vincent, I don't think your employer gets happy from the way
>>> you treat
>>> paying customers... As a relative freeloader (I'm only a silver
>>> club member)
>>> I know to silently put up with your short fuse, but it's just not a
>>> pretty
>>> sight to see you dis a real customer...
>>>
>>
>> Ummm.. I don't have a short fuse.  Ask my daughter... I'm
>> exceptionally patient.  =)  Unfortunately, my problem isn't that I
>> have a short fuse, it's that I call things as I see them without
>> sugar coating it (ask my wife... this is definitely one "fault" that
>> she probably could do without).  I wasn't "dissing" Bob.  I was
>> making an observation.  Someone either did sucker him into thinking
>> that he would get new versions of software with CS, or he
>> misunderstood what the extended support lifetime is.  That's not
>> "dissing" him.  That's simply saying that someone told him something
>> that wasn't true, or he just didn't understand something that should
>> have been clear enough.  *I* haven't seen any thing that even
>> remotely suggests software will be updated to the latest version  
>> in CS.
>>
>
> Ok, I apologise for drawing conclusions too quickly, that's one of my
> shortcomings ;-)

No worries.

> As it is though, your responses would actually need constant  
> monitoring to
> avoid negative consequences from misunderstanding your intention...

Well, that is a problem with speaking bluntly (one of my  
shortcomings).  Unfortunately, with my workload and the amount of  
email I have to wade through on a daily basis, I don't  have the  
luxury of flowery responses and re-reading them three times before  
sending them out to make sure that no one will misunderstand or  
misinterpret any part of it.  Due to time being a luxury I usually do  
not have, my responses need to be more or less pointed and they don't  
get "proofed" at all.

>> And my employer is quite happy with me, thankyouverymuch.  In fact,
>> sitting on this list and even replying to these mails is not part of
>> my job and I am not required to be here at all, so, having said, that
>> I'm going above and beyond the call of duty to even read this list,
>> nevermind respond on it.  My employer appreciates that singular
>> dedication; it's unfortunate you do not.
>>
>
> I do appreciate it, I was merely speculating about Mandriva's  
> opinion...

In 5 years I have never been chastised.  Heck, if you read cooker  
you'll see that I'm one of the more tolerant Mandriva employees.  =)

>>> And about the other distro's, there never a need to follow a bad
>>> example. If
>>> you can think up a better solution, that can help you stand out
>>> from the
>>> others, it's not a bad thing to stand out positively in a  crowd!
>>>
>>
>> Give me the same resources the other distros have and I guarantee you
>> we will stand out from the crowd.  Given the lesser resources at my
>> disposal compared to most other distros, I think we're doing a damn
>> fantastic job.  If I was on par with, say, the SUSE team, what we
>> could accomplish would literally blow your mind.  =)
>>
>
> I'd love to see that! Why doesn't mandriva give you more resources?  
> They've
> just incorporated 2 other distros, can't they spare a few resources to
> enhance such a vital part of their support?

Why?  Can't answer that.  I don't know.  This is something that has  
been an issue for a while.  I don't really want to elaborate on it  
too much because I don't want folks to think I'm whining about my  
bosses.  Suffice it to say, it's not something I've given up on, and  
it has been ongoing for a while.  I can concede that additional  
resources were made available, but I don't think they are enough  
while others think they should be sufficient.

>> Until then, I have to keep a tight reign on resource expenditure to
>> make sure the best job possible can be accomplished with what I have
>> at my disposal and that is a fine line to walk to keep everyone as
>> happy as possible.
>>
>
> I believe the policy has just been pushed off the fine line, it is  
> no longer
> sufficient to provide adequate support. Since this is nothing  
> personal,
> if I were you I'd inform upper management that if you don't get  
> some help,
> people are going to leave Mandriva due to lack of security support.  
> In my
> opinion that is currently not an unrealistic scenario.

And it is one that has been presented.  The current situation is not  
for lack of trying.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed