Hi, On Tue, Mar 11, 2008 at 09:43:30PM -0500, Frank Bulk - iNAME wrote: > By not making the update available until the 6 month mark has been met, > service providers are not able to choose their own update cycle. Rather, by > restricting the updates to every 6 months, Cisco has reduced the update > cycle to, at most, once every 6 months. So this reduces flexibility for the > customer, but benefits Cisco by reducing the number of test cycles and > updates they need to post, i.e. cost savings for them.
This has been already answered, so stop ranting.
Cisco will fix the bugs as soon as they are discovered, and make new images
available. As usual.
What they are *not* doing is "post security advisories every few weeks
for things that are not (yet) known out in the wild". Because when they
do that, people *will* go out trying to find the exploit, and then everybody
has to scramble to upgrade, multiple times a year.
Personally, I think there is no way besides "do not code security holes"
to make everybody happy - and I'm fine with the proposed schema. Provided
the mechanism "knowledge appears in the wild -> immediate release" works.
gert
--
USENET is *not* the non-clickable part of WWW!
//www.muc.de/~gert/
Gert Doering - Munich, Germany [EMAIL PROTECTED]
fax: +49-89-35655025 [EMAIL PROTECTED]
pgpNq9VBgk7yG.pgp
Description: PGP signature
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
