ISS X-Force Security Advisories on Checkpoint Firewall-1 and VPN-1

Why is that bad? I have no objection to giving vendors a reasonable
amount of time to fix problems before announcing the whole. Or is your
point that two days hardly seems like enough time to develop -- and
*test* -- a fix?

    --Steve Bellovin, http://www.research.att.com/~smb

My point is that is very unlikely that both bugs had been discovered by ISS
within the same time frame. Two days is also little time do develop and
test, which raises the suspicion on this issue.

I'm not against notification before disclosure, but it seems that the dates
on this announcement might have been changed in order to make the solution
appear to be developed in very little time. ("See ma, I'm damn fast")

Rubens

Two days is plenty if it's a Homer Simpson-esque "D'Oh!" bug. Probably
not if it's something that requires some regression testing.

Two days is plenty if it's a Homer Simpson-esque "D'Oh!" bug. Probably
not if it's something that requires some regression testing.

my memory from some decades in software product world is that
*any* change requires regression testing, especially the quick
little, "it won't affect anything", changes.

randy

All bugs reduse to that, eventually, don't they?

Very few do. Most of the time, the appropriate quote is:

"So, there is a curse? That's interesting." -- Captain Jack Sparrow.

:slight_smile: