Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Do you run a Movabletype blog? » Doh
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
What I want to know »
« What the spamers deserve.  
AuthorAll Replies


justin
Australian
join:1999-05-28
Brooklyn, NY
reply to koitsu
Re: Doh

really? that doesn't sound like any OSS projects I can imagine. Are you sure you are not confusing requests for features you want, which may of course be ignored, with notification of important bugs and security problems?


koitsu
Premium
join:2002-07-16
Mountain View, CA

I've spent too many years working with OSS to confuse the two. The response I speak of I've received from members of the Apache team (re: RFC931/1413 flaw which could lead to a buffer overflow and still exists today, re: zombie processes caused on many systems in 1.3.29), developers of SpamAssassin (re: spamd leaving zombie processes around on BSD systems), BIND 8.x (re: potential security hole: zone transfer tempfiles put in main root dir only when using key-based authentication, requiring the daemon to have full rwx access to /etc/namedb, rather than putting them in the appropriate zone directory from each zone directive), GNU screen (re: code checking for ~/.nethackrc despite "nethack off" being specified in .screenrc), PHP 4.x (re: returning status code of 200 regardless of what Apache says is a legitimate command; still exists today), FreeBSD sendmail updates (re: expanding etc/mail/Makefile to support sendmail's "cidrexpand" script so one can use CIDR notation in etc/mail/access; this is more of a feature, but the response was a real let-down) and numerous other mainstream applications.

I've been trying to keep a list of all the issues I've reported which go either unresponded to or illicit the standard "You have the source, fix it yourself" response, but I run into stuff too often to maintain a coherent list...

I'm just one guy with very interesting experiences with the OSS community, most of them negative. But it still warms my heart (honestly) when I see an OSS developer step in and say "Thanks for reporting this! I'll provide and commit a patch in a few minutes," or simply push out a new release.

Anyways, without getting too off track, my point is that peoples' responsibilities shouldn't be nullified whether or not the application is free or commercial.
--
Making life hard for others since 1977.
Forums » Do you run a Movabletype blog?What I want to know »
« What the spamers deserve.  


Tuesday, 24-Nov 10:33:18 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [95] New AT&T Ad Campaign Hits Back At Verizon
· [66] New Bill Takes Aim At Higher Verizon ETFs
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [27] Frontier Increases Modem Rental Fee
· [13] Vivendi In Way Of Comcast's NBC Desires
· [13] Charter Still Fighting With Creditors
· [7] Monday Morning Links
· [6] FCC 'Forgets' There's Limited Competition
· [5] Senators Want ACTA Made Public
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Big Bank Alternative to Bank of America? [General Questions]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· netTalk tk6000 [VOIP Tech Chat]
· CTV & Canwest ask CRTC to order blocking of U.S. programs [TekSavvy]
· Bell's Network Management practices page [TekSavvy]
· What to use while demonoid is down? [Filesharing Software]
· Getting ready to pull the trigger, still have cold feet. [VOIP Tech Chat]
· iNum and 911 [VOIP Tech Chat]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]