Why Mozilla? Why Not?
Via Exchange Security: Mozilla Vulnerability Timeline. Impressive.
Paul (Robichaux, who publishes the Exchange Security blog) criticizes Mozilla on a few things, such as not having "a robust system for notifying people of updates and, optionally, pushing them to affected machines." I'm running Mozilla FireFox, and even after upgrading to 0.9.2, I have a red square in the bottom-right of the browser that says critical updates are available. When I went up to Mozilla.org to download the 0.9.2 package, I experienced no delays and the setup was smooth. And this is for free software that's technically in beta, but embraces standards better than IE.
I think one of the benefits of documenting the patching of this vulnerability is to show a counterpoint to the "security through obscurity" that Microsoft relies on in many instances in the time before they've published a security patch.
Comments
Posted by: dziner | July 12, 2004 6:07 PM