|
Security Bugs and Full Disclosure |
|
|
|
Source: kerneltrap - Posted by Bill Keys
|
In an announcement for the 2.6.25.10 stable kernel, Greg KH noted, "it contains a number of assorted bugfixes all over the tree. And once again, any users of the 2.6.25 kernel series are STRONGLY encouraged to upgrade to this release." The emphasis on the word strongly led to a lengthy discussion about how security fixes are handled in the Linux Kernel. Linus Torvalds replied, "I personally consider security bugs to be just 'normal bugs'. I don't cover them up, but I also don't have any reason what-so-ever to think it's a good idea to track them and announce them as something special." Later in the thread he went on to explain, "one reason I refuse to bother with the whole security circus is that I think it glorifies - and thus encourages - the wrong behavior.
This article looks at the how the Linux kernel developers handles security fixes. What do you think about how the kernel team releases security updates? Is there a better way or model?
Read this full article at kerneltrap
Only registered users can write comments. Please login or register. Powered by AkoComment! |