10-Day Patch Guarantee Not Mozilla's Policy
narramissic writes "Mozilla has officially backpedaled from a pledge made at Black Hat by the company's director of ecosystem development, Mike Schaver, to fix any critical security bugs in the browser within 'Ten ****ing Days.' On Friday, Mozilla security chief Window Snyder wrote in a blog posting that the 10-day pledge is not Mozilla's policy, saying 'We do not think security is a game, nor do we issue challenges or ultimatums.' And today, the open source browser maker issued a statement retracting the pledge."
Making that sort of pledge is rather rash. I am not saying it can't be done, but I don't see it as simple to fix anything anytime.
Questions you have to ask are;
Is it really a bug?
Can it really be reproduced?
etc etc
Being timely in bugs is good. But not all crashes are the result of bad software. You have to be sure your fix doesn't turn another thing into a bug. They would soon end up chasing after every little bit of dust and lose sight of their real work.
Sorry about the writing. Robot fingers, you know? Cliff Steele in DOOM PATROL #23
I don't think that that follows. They've made a few mistakes, and this was one of them. They shouldn't make ultimatums like that. That said, I have a feeling that they'll continue to be a lot more responsive on the patching front than Microsoft, and I think that the point has been made, even if they won't stick to a set time-line.
The Debian thing is not a strike against Mozilla. Their stance is correct and clear. You can't have someone else using your trademark to cover something that they are supporting. If the Debian team introduces a bug or something into their build of Firefox, Mozilla's brand will suffer. That's why Mozilla wanted Debian to rebrand it.
My mayor ran on the promising of "fixing any pothole within 24 hours of discovery." Of course the roads are still filled with potholes. Turns out, it was 24 hours of any confirmed pothole, which is trivially easy as the pothole confirmation team is as slow/backed up as the pothole filling team.
Your ad here. Ask me how!
to hold up to the 10-day pledge but in the end, if something major holds back a fix, are we all going to bash them for missing the 10-day pledge? I doubt it. After all, we are not talking about Microsoft. These people are trying to do the best job possible and don't have to consider how the browser fix would interfere with some feak'n gumball machine driver that has IE code in it.
But she's right in that they really shouldn't be making statements like that without having discussed this with their team and doing so could be considered a challenge to others. Not something you want to do with a company willing to pay billions just to purchase marketshare let alone how much they'd be willing to put into ads and other FUD should a fix take 241 hours.
LoB
"Anyone who stands out in the middle of a road looks like roadkill to me." --Linus
Once Konqueror gets a Windows build, it's game-over for Firefox. It's a better browser - it just hasn't, until recently, run on Windows.
I happen to agree it's a much better browser, and a very good file manager, among other things, BUT there's nothing to make me think that once it becomes popular enough, the exact same thing won't happen to it. Popular software gets sucked into the corporate venus fly trap faster than a trailer park gets sucked into a tornado. The nice thing about all this open source though, is that nobody can claim exclusivity. We can always make something similar, a little bit better, and put a different name on it. I was under the impression that's the idea behind GPL and BSD and Creative Commons, etc. to begin with. So we can simply forget about the guy who takes a wrong turn, instead of following him over the cliff.
What?