Gentoo Archives: gentoo-security

From: Carsten Lohrke <carlo@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] All done and settled
Date: Wed, 10 Nov 2004 15:49:07
Message-Id: 200411101648.34807.carlo@gentoo.org
In Reply to: [gentoo-security] All done and settled by Peter Simons
1 On Wednesday 10 November 2004 16:02, Peter Simons wrote:
2 > Which means that I have totally fucked up the job my clients
3 > trusted me to do and when the details of this problem reach
4 > the consciousness of the "general public", there will be
5 > questions asked and I will look like an idiot to my clients,
6 > not like a hero who "blew the whistle". Because they
7 > couldn't care less about technical details, they only care
8 > about security.
9
10 That's the difference between relying on a opensource distro and a commercial
11 counterpart. In the latter case you've someone, who can be held liable, since
12 you (or your customer) paid for it. Unless you provide a fix, your customer
13 is absolutely right to blame you, but you're wrong, if you think you can
14 shift it upon someone else. Clamouring doesn't help, do a better job next
15 time. It is your economical risk.
16
17
18 Carsten