incubator-ooo-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Rob Weir <robw...@apache.org>
Subject Re: Neutral / shared security list ...
Date Tue, 25 Oct 2011 16:26:35 GMT
On Tue, Oct 25, 2011 at 12:20 PM, Florian Effenberger
<floeff@documentfoundation.org> wrote:
> Hi,
>
> Rob Weir wrote on 2011-10-25 18:11:
>>
>> Sorry, but you build an incredible about of distrust in others if you
>> express such irrational distrust in AOOo.  I'd have extreme hesitation
>> to work with anyone who exhibs such vehement distrust of an 11 year
>> old open source foundation that produces 5 of the top 10 open source
>> projects, and which has a stellar reputation in the industry,
>> including its treatment of security vulnerabilities.
>
> where did I express distrust in AOOo? I was explaining what neutral means.
> Is there anything wrong in the explanation of neutrality in this case?
>
> One could also say you express distrust to people who have been involved
> with OpenOffice.org for nearly a decade. But insults like these lead to
> nowhere.
>

My point is that neutrality does not increase trust.  You may say
Apache is not neutral, but I say Apache is trusted in this industry in
security matters, with security researchers, users and corporations,
and this trust is far greater than any trust you will have with a new
ad-hoc little security list that you create today, with ad hoc
governance.

I'm more concerned with trust than with neutrality.  Users are more
concerned with trust.  Security reporters are more concerned with
trust.  And I recommend that you start being more concerned with
trust, users and security.

It is mind boggling that we're having a discussion about an important
topic -- how we handle security vulnerabilities -- and the discussion
is being led based entirely on non-security considerations, without
hardly a mention of users, and instead dwelling on one party's
paranoia.  This does not make sense.

-Rob

> Florian
>
> --
> Florian Effenberger <floeff@documentfoundation.org>
> Steering Committee and Founding Member of The Document Foundation
> Tel: +49 8341 99660880 | Mobile: +49 151 14424108
> Skype: floeff | Twitter/Identi.ca: @floeff
>

Mime
View raw message