On 18/12/2009 3:09 AM, LuKreme wrote:
> On 18-Dec-2009, at 00:24, Daryl C. W. O'Shea wrote:
>> From the data we have from mass-checks we are erring a very small amount
>> on the side of caution by not disabling the whitelists by default.
> 
> 
> I guess that the real issue that I have with the whole HABEAS thing is the 
> magnitude of the default scores. −4 and −8 caused issues that would never 
> have arisen had the defaults been −0.4 and −0.8. Or even −1 and −2.

The scores have been decreased in the upcoming proposed release ruleset.
 Not to -0.4 and -0.8, but they're no longer -4 and -8.  I'm sure that
we'll get to (it's been -4 and -8 for years, we're not in a huge rush to
do anything now) decreasing them in the 3.2.x sa-update ruleset also
once we've firmed up an opinion of what they should be going forward.

Please stop beating the -4 and -8 horse.  We agree.

Daryl


Reply via email to