Re: Debian Investigation Report after Server Compromises
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Tue, Dec 02, 2003 at 04:11:33PM -0500, Paul Morgan wrote:
> Ther is always a conflict between security and openness. MS's approach
> has always been not to say anything until a fix has been propagated; they
> are often criticized for that, but I'm sure they'd be deluged in lawsuits
> from compromised system owners if they advertised the exploit to bad guys
> before they had a fix.
Microsoft could easily sidestep those by pointing to their EULA: You
agree not to sue them due to faults in their software.
- --
.''`. Paul Johnson <baloo@ursine.ca>
: :' :
`. `'` proud Debian admin and user
`- Debian - when you have better things to do than fix a system
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
iD8DBQE/zYpXUzgNqloQMwcRAvnNAJ0V6Ehrk6oydphWjyCnZZygciUawwCgx3W9
urJRNsxKgdRdxqNyR3wG9Wk=
=FWZX
-----END PGP SIGNATURE-----
Reply to: