<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Are we taking vulnerabilities less seriously?</title>
	<link>http://www.tssci-security.com/archives/2007/03/18/are-we-taking-vulnerabilities-less-seriously/</link>
	<description>top secret/secure computing information</description>
	<pubDate>Sat, 11 Oct 2008 00:40:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.3</generator>

	<item>
		<title>By: James</title>
		<link>http://www.tssci-security.com/archives/2007/03/18/are-we-taking-vulnerabilities-less-seriously/#comment-217</link>
		<dc:creator>James</dc:creator>
		<pubDate>Mon, 19 Mar 2007 07:43:19 +0000</pubDate>
		<guid>http://www.tssci-security.com/archives/2007/03/18/are-we-taking-vulnerabilities-less-seriously/#comment-217</guid>
		<description>Noone at OpenBSD is treating availability as unimportant, but it is a lesser concern, they are classifying crashes as an issues outside of security.

It is a thing they mark on their Errata, but it is marked as reliability rather than security, because they are two different things.

Yes, the Integrety of the data is the most important thing to a security minded individual, but those people do not ignore Availabilty, they would just rather have that Integrety if they are forced to choose between the two, would you rather have invalid data availabile to you?

The OpenBSD team did fix the issue in a timely manner, and they classified it how they judged it and moved on, it is random analysts who are sitting around muttering.  That their quick evaluation proved to be false is a suprise, but not something I am concern with - they have never once told people to not keep their system up to date, quite the opposite, they always say to run -stable.</description>
		<content:encoded><![CDATA[<p>Noone at OpenBSD is treating availability as unimportant, but it is a lesser concern, they are classifying crashes as an issues outside of security.</p>
<p>It is a thing they mark on their Errata, but it is marked as reliability rather than security, because they are two different things.</p>
<p>Yes, the Integrety of the data is the most important thing to a security minded individual, but those people do not ignore Availabilty, they would just rather have that Integrety if they are forced to choose between the two, would you rather have invalid data availabile to you?</p>
<p>The OpenBSD team did fix the issue in a timely manner, and they classified it how they judged it and moved on, it is random analysts who are sitting around muttering.  That their quick evaluation proved to be false is a suprise, but not something I am concern with - they have never once told people to not keep their system up to date, quite the opposite, they always say to run -stable.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.160 seconds -->
