[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Full-Disclosure] Is Mozilla's "patch" enough?
- To: Florian Weimer <fw@xxxxxxxxxxxxx>
- Subject: Re: [Full-Disclosure] Is Mozilla's "patch" enough?
- From: Aviv Raff <avivra@xxxxxxxxx>
- Date: Mon, 12 Jul 2004 20:58:57 +0200
On Mon, 12 Jul 2004 20:34:44 +0200, Florian Weimer <fw@xxxxxxxxxxxxx> wrote:
> * Aviv Raff:
>
> > Security patches shouldn't be overridden unless intended too (i.e
> > uninstalled).
>
> This is not standard industry practice. Especially if a patch might
> break previously working configuration, I completely agree that it's
> correct.
That's why there should be a way to uninstall the patch, as I wrote.
> For most people, having a working system is more important than having
> a secure system.
I agree.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html