Mozilla security process criticised
Monday, May 23rd, 2005Ben Goodger argues for the use of Mozilla binaries rather than vendor binaries because binaries have security patches applied earlier:
If security is important to you, this demonstration should show that browsers that are redistributions of the official Mozilla releases are never going to give you security updates as quickly as Mozilla will itself for its supported products.
.
Christopher Aillon criticises this as bad practice:
Other projects make sure that the vendors know of a security vulnerability, supply the patch and new tarball (if applicable, which it is in mozilla.org’s case), give a brief period of time for the vendors to catch up, and then do a synchronous release with them at a planned time.
(via Slashdot)
Popularity: 62% [?]