<?xml version="1.0" encoding="UTF-8"?><!-- generator="lyceum/1.0.2" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Bug fix scorecard</title>
	<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/</link>
	<description>Truth happens</description>
	<pubDate>Wed, 20 Aug 2008 20:29:47 +0000</pubDate>
	<generator>http://lyceum.ibiblio.org/?v=1.0.2</generator>

	<item>
		<title>by: Security Spin Cycles - The Capslock Assassin</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-27213</link>
		<pubDate>Wed, 17 Oct 2007 02:34:27 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-27213</guid>
					<description>[...] Jeff Jones posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their &#8220;Truth Happens&#8221; blog back in August, which itself quotes a post on Lxer.com. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] Jeff Jones posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their &#8220;Truth Happens&#8221; blog back in August, which itself quotes a post on Lxer.com. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Mark Ryder</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-27207</link>
		<pubDate>Wed, 17 Oct 2007 01:09:04 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-27207</guid>
					<description>You guys are amazing, thinking that fixing more bugs is a good thing. What are you doing to reduce the number of security bugs in the first? Shipping junk, and fixing lots of bugs later is simply "cowboy coding" and nothing to be proud of.</description>
		<content:encoded><![CDATA[<p>You guys are amazing, thinking that fixing more bugs is a good thing. What are you doing to reduce the number of security bugs in the first? Shipping junk, and fixing lots of bugs later is simply &#8220;cowboy coding&#8221; and nothing to be proud of.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: totalnetsolutions.net &#187; Microsoft VS. Red Hat - Why did they go there?</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-27169</link>
		<pubDate>Tue, 16 Oct 2007 19:45:09 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-27169</guid>
					<description>[...] I saw this post from Jeff Jones over at Microsoft today. He mentions that Red Hat Enterprise Linux 4 recently patched their 1000th vulnerability, and provides a quote from Truth Happens(direct link to post), which is a Red Hat blog. I suggest you at least read Jeff&#8217;s post, since he quotes the relevant point of the Truth article. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] I saw this post from Jeff Jones over at Microsoft today. He mentions that Red Hat Enterprise Linux 4 recently patched their 1000th vulnerability, and provides a quote from Truth Happens(direct link to post), which is a Red Hat blog. I suggest you at least read Jeff&#8217;s post, since he quotes the relevant point of the Truth article. [&#8230;]
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Wilsonz</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-22426</link>
		<pubDate>Tue, 18 Sep 2007 21:04:45 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-22426</guid>
					<description>This post looks like FUD to me or at least its a great example statistics published in an incomplete manner. The same data published as a ratio of fixes by category to bugs found would tell the story more accurately. Maddog's post addresses the other reason this comparison is likely invalid.</description>
		<content:encoded><![CDATA[<p>This post looks like FUD to me or at least its a great example statistics published in an incomplete manner. The same data published as a ratio of fixes by category to bugs found would tell the story more accurately. Maddog&#8217;s post addresses the other reason this comparison is likely invalid.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Maddog</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18913</link>
		<pubDate>Tue, 28 Aug 2007 05:03:44 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18913</guid>
					<description>Vista not having much to fix? Or isn't it more like they don't announce everything they try to fix? Microsoft has a history of not disclosing bugfixes (see "Skeletons in Microsoft’s Patch Day closet"; http://blogs.zdnet.com/security/?p=316) and this controversial practice will definitely skew Jeff's numbers. That renders Jeff's "scorecard" practically useless.</description>
		<content:encoded><![CDATA[<p>Vista not having much to fix? Or isn&#8217;t it more like they don&#8217;t announce everything they try to fix? Microsoft has a history of not disclosing bugfixes (see &#8220;Skeletons in Microsoft’s Patch Day closet&#8221;; <a href="http://blogs.zdnet.com/security/?p=316" rel="nofollow">http://blogs.zdnet.com/security/?p=316</a>) and this controversial practice will definitely skew Jeff&#8217;s numbers. That renders Jeff&#8217;s &#8220;scorecard&#8221; practically useless.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Alan</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18533</link>
		<pubDate>Sat, 25 Aug 2007 03:04:24 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18533</guid>
					<description>Ummm.  So since Red Hat had more vilnerabilities than Microsoft, they did a better job??  That's the way to spin it.  :)

Now if they had the same vulnerabilities discovered and one fixed more than the other, then that is a win.  Otherwise Windows Vista is the clear winner here for not having much to fix.</description>
		<content:encoded><![CDATA[<p>Ummm.  So since Red Hat had more vilnerabilities than Microsoft, they did a better job??  That&#8217;s the way to spin it.  <img src='http://truthhappens.redhatmagazine.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now if they had the same vulnerabilities discovered and one fixed more than the other, then that is a win.  Otherwise Windows Vista is the clear winner here for not having much to fix.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Josh</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18513</link>
		<pubDate>Fri, 24 Aug 2007 21:59:06 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18513</guid>
					<description>So, uh, is Microsoft's numbers so low because substantially fewer vulnerabilities were discovered, or was it because they are slow to fix things.  From other posts on Jeff's blog concerning days of vulnerability, MS also comes out in the lead, suggesting that they are fixing the bugs as they arise rather than avoiding fixes.

Also, isn't it a bit misleading to suggest that Red Hat, with 1/40th the employees is actually fixing all of those vulnerabilities.  I mean, shouldn't some credit go to the FOSS community that also contributes to fixing vulnerabilities rather than giving redhat all of the credit.</description>
		<content:encoded><![CDATA[<p>So, uh, is Microsoft&#8217;s numbers so low because substantially fewer vulnerabilities were discovered, or was it because they are slow to fix things.  From other posts on Jeff&#8217;s blog concerning days of vulnerability, MS also comes out in the lead, suggesting that they are fixing the bugs as they arise rather than avoiding fixes.</p>
<p>Also, isn&#8217;t it a bit misleading to suggest that Red Hat, with 1/40th the employees is actually fixing all of those vulnerabilities.  I mean, shouldn&#8217;t some credit go to the FOSS community that also contributes to fixing vulnerabilities rather than giving redhat all of the credit.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Maddog</title>
		<link>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18301</link>
		<pubDate>Thu, 23 Aug 2007 08:30:44 +0000</pubDate>
		<guid>http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-18301</guid>
					<description>Excellent reverse spin on Microsoft's data! This just goes to show that Microsoft is spinning data to make its products look good. Jeff Jones should stop pretending he's a security guy and proclaim himself as Microsoft's marketing guru, their UberFUDMeister!</description>
		<content:encoded><![CDATA[<p>Excellent reverse spin on Microsoft&#8217;s data! This just goes to show that Microsoft is spinning data to make its products look good. Jeff Jones should stop pretending he&#8217;s a security guy and proclaim himself as Microsoft&#8217;s marketing guru, their UberFUDMeister!
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
