[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] OT brief note on: CERT AdvisoryCA-2003-25Buffer Overflow in Sendmail



At 11:30 AM 9/19/2003, you wrote:
>
> at least with zeffie.  i know i can call at 5 am and he answers the
> phone :)  hell, it even works in the reverse directory of the white
> pages.
>

At least with virtually every single other person on this list that
offers commercial services for the RaQ, I have not seen any of them so
consistently make disparaging remarks about their competitors. Actually,
I don't think I can recall any of them making unfounded negative
comments about any of their competitors.


I have seen much help from zeffie in the past. I am quite surprised by his response this time round. I do understand the gist behind his statement to the person he started his comment to. My belief is that his basic point being, that the person that created the operating system is better prepared to make modifications to it. Anyone that has been around a while should know by now that the operating system on most Raq's were developed from RedHat 6.x and that Cobalt removed a number of "features" from the operating system as it was being built for an appliance and would not be needed or would be a security risk. Many updates to the operating system are not current versions, but modified versions of what were running on the system.

I stand with him on the point that I would rather an update come from the same source as the operating system on the computer. That said, I understand that most of the people that created it are now gone. Among them, Taco, "in Europe" as Zeffie used the term. Taco has released many non official packages while he was an employee and the packages were refered to by Cobalt employees in the past. As he no longer works for Sun/Cobalt he has not had the time to invest in helping "former customers". This can be said for some others such as Bruce who has helped so many of us and still does so as he has time.

I do appreciate those who create us packages for our systems. But where do we stand if they decide to stop, after all, they are not responsible for the support of our product. Second, do they know the intricacies of the operating system built for the Cobalt systems, that is the modified RedHat operating system? Does the package they create break something else within the system that was intentionally removed to prevent a security risk?

I thank everyone that helps and has helped. I just wish Sun would get off their ass and give us some patches in a timely manner and tell us they are doing something when it is going to be a bit before the patch is really. A bit is not months though.

David
A Raq, Owner, Operator, and User



--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.