1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Interesting study. I like the premise of it. However, I'm not sure I |
5 |
agree with their method. From the article: |
6 |
|
7 |
"For instance, if a distribution fixed an issue on the earliest date, it |
8 |
would receive a score of 100 for that issue; if it was the last vendor to |
9 |
fix the issue, it would get a score of 0. One can then average the scores |
10 |
after evaluating the 30 issues." |
11 |
|
12 |
So this is just a ranking, with no quantitative results. What I'd really |
13 |
like to know are the distributions' average response times for the High |
14 |
and Moderate vulnerabilities. |
15 |
|
16 |
While Gentoo might be 6th, I'd like to know how much slower Gentoo gets |
17 |
out patches than Ubuntu, Fedora, and/or RHEL. |
18 |
|
19 |
|
20 |
- -Vince |
21 |
|
22 |
|
23 |
- -- |
24 |
Vincent Rivellino |
25 |
GPG Key ID: 62BFEBE4 |
26 |
https://cuz.cx/gpg |
27 |
|
28 |
|
29 |
On Mon, August 7, 2006 07:42, Wolfram Schlich wrote: |
30 |
> Hi, |
31 |
> |
32 |
> |
33 |
> I just stumbled over an article from SearchSecurity.com which was linked |
34 |
> to in a heise newsticker posting that tries to analyze how fast |
35 |
> distributions react to security vulnerabilities: |
36 |
> |
37 |
> http://tinyurl.com/lplfb |
38 |
> |
39 |
> |
40 |
> Quick chart: |
41 |
> |
42 |
> |
43 |
> Rank Distro Points/100 |
44 |
> ---- ------------------------- ---------- |
45 |
> 1. Ubuntu 76 |
46 |
> 2. Fedora Core 70 |
47 |
> 3. Red Hat Enterprise Linux 63 |
48 |
> 4. Debian GNU/Linux 61 |
49 |
> 5. Mandriva Linux 54 |
50 |
> 6. Gentoo Linux 39 |
51 |
> 7. Trustix Secure Linux 32 |
52 |
> 8. SUSE Linux Enterprise 32 |
53 |
> 9. Slackware Linux 30 |
54 |
> |
55 |
> |
56 |
> Rank 6 out of 10 is not a great result -- at least we beat SUSE ;) |
57 |
> |
58 |
> |
59 |
> Any comments or thoughts about this? |
60 |
> Can we become better? |
61 |
> Are we maybe better than the author pretends? |
62 |
> Does the security team currently face serious problems that need to be |
63 |
> solved, be it inside or outside the security team? |
64 |
> |
65 |
> I am just curious and would be glad to get some feedback :) |
66 |
> -- |
67 |
> Regards, |
68 |
> Wolfram Schlich <wschlich@g.o> |
69 |
> Gentoo Linux * http://dev.gentoo.org/~wschlich/ |
70 |
> -- |
71 |
> gentoo-security@g.o mailing list |
72 |
> |
73 |
> |
74 |
|
75 |
|
76 |
-----BEGIN PGP SIGNATURE----- |
77 |
Version: GnuPG v1.4.4 (GNU/Linux) |
78 |
|
79 |
iD8DBQFE12eKhUAfdmK/6+QRAm4sAJ9U4hDbql8b5Du7ELWTclnBdwXONACghkRk |
80 |
PLfad2L0hjQZ99puzngf4nU= |
81 |
=/aSm |
82 |
-----END PGP SIGNATURE----- |
83 |
|
84 |
-- |
85 |
gentoo-security@g.o mailing list |