On Fri, Dec 10, 2004 at 02:19:40PM -0500, Luke Youngblood wrote:
> Sorry, I didn't mean to ruffle so many feathers in this mailing list.  It's
> just that I am 1 week into a 2 week implementation of Nessus as a scanning
> solution and all of a sudden I have to start over and there are new costs I
> need to present to management, where previously I had sold them on the idea
> of Nessus being free.

You seem to have misunderstood the concept :

Nessus is *still* free.  The only difference is that starting 1st,
you'll have a 7 days delay between the time Tenable writes new plugins
and the time you'll get the updates AND you need to register on the
Nessus website (for free).

If you can not wait seven days, you can buy a subcription which will
give you direct access to the plugins we write.

If you installed Nessus 2.0.x and/or Nessus 2.2.0 and for some reason
can not upgrade, you can _manually_ register your activation code 
on plugins.nessus.org (as the instructions in the registration email
say) and you'll get a URL where you can download the plugins. At that
point, you simply need to modify nessus-update-plugins to change one URL
by another.


[...]
> FWIW I can sympathize with the developers if commercial builds of Nessus are
> stealing their code and not honoring the GPL, but one analogy I can come up
> with is this:  How would you feel if the Apache Foundation all of a sudden
> said that you had to "subscribe" to get security updates to Apache?  There
> would be an uproar.

That has nothing to do with it. A security update in Apache means that
someone at Apache goofed up, there is a vulnerability, and bad guys can
use it to gain the control of your server. The Apache Foundation then
fixes the issue and people upgrade.

A "security update" in Nessus is a check to detect flaws in another
vendor product. A much better analogy would be "what if all of a sudden,
you had to pay to get updates to your anti-virus ?".


                                -- Renaud
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to