main

Mozilla: 10-day patch guarantee 'not our policy'

Daniel Fleshbourne   on 07 August 2007 - 17:44 · 16 comments & 7041 views

Advertisement (Why?)
The open-source browser maker was forced to issue a statement Monday, retracting a pledge attributed to the company's director of ecosystem development, Mike Schaver, to fix any critical security bugs in the browser within "Ten Days." Security researcher Robert Hansen said that Schaver had made the pledge at a late-night pajama party, hosted at last week's Black Hat conference in Las Vegas.

When Hansen said he doubted that this was possible, Shaver apparently backed up his pledge in writing: putting it on a business card with an arrow linking to his mobile phone number. "I told him I would post his card -- and he didn't flinch. No, he wasn't drunk. He's serious," Hansen wrote in a Friday blog posting. [Warning: URL and image contain expletive.] On Friday, Mozilla security chief Window Snyder offered a refinement to Shaver's late-night scrawl. "This is not our policy," she wrote in a blog posting. "We do not think security is a game, nor do we issue challenges or ultimatums."

View: The full story
News source: ComputerWorld

Post a comment · Send to friend Comments · There are 16 additional comments
#1 vetmarkjensen on 07 Aug 2007 - 18:17
From the blog (if you follow the links)
Quote -
They said the recent rollouts were actually slower than they would have liked them to be, even though they were only a week and a half apart. Further, they said that they could roll out any critical patches within 10 days. Not one to let challenges go untested I called BS.

At this point Mike Shaver threw down the gauntlet. He gave me his business card with a hand written note on it, laying his claim on the line. The claim being - with responsible disclosure Mozilla can patch and deploy any critical severity holes within “Ten F------ Days”
It sounds like the "Not one to let challenges go untested I called BS" statement from the source blogger may have been a watered down summary of a chest-thumping match between someone responsible for security at Mozilla and someone who challenged/prodded him.

A very human reaction to what was likely a testosterone-driven discussion.

10 days or less is a great goal, but I can see the lawyer-types crawling all over this to make sure it is announced that this is not a "policy".
(4 replies) #2 Croquant on 07 Aug 2007 - 18:22
...had made the pledge at a late-night pajama party...

What the hell kind of conference was this?
#2.1 SacrificialSoldier on 07 Aug 2007 - 18:38
Yeah! I know! What is with that?
#2.2 shockz on 07 Aug 2007 - 18:54
Quote - (SacrificialSoldier said @ #2.1)
Yeah! I know! What is with that?


LOL. I was just about to post the same thing.
#2.3 +Digix on 07 Aug 2007 - 20:15
#2.4 Doli on 08 Aug 2007 - 02:59
Quote - (Digix said @ #2.3)


Ahh Minjas (ninja midgets)
#3 norky on 07 Aug 2007 - 20:34
director of ecosystem development sounds pretty cushy.
#4 XerXis on 07 Aug 2007 - 22:09
director of ecosystem at a pajama party sounds even worse
(1 reply) #5 Ravensworth on 08 Aug 2007 - 07:21
Robert Hansen said that Schaver had made the pledge at a late-night pajama party

These are guys, right?
#5.1 travelcard on 08 Aug 2007 - 07:33
He meant a 10 day patchwork quilt guarantee. You know what these sewing circles are like.
#6 cork1958 on 08 Aug 2007 - 12:47
Hmm? Imagine that. Got so popular, they have to find a way to back out of part of what they are known for!!



#7 Magallanes on 08 Aug 2007 - 13:00
The World will need more on-time patches and less pajama parties!.



(1 reply) #8 LaXu on 08 Aug 2007 - 14:02
Quote -
[Warning: URL and image contain expletive.]


Hahaha. Don't you just love the PC crew.
#8.1 vetmarkjensen on 08 Aug 2007 - 18:43
It has probably a lot more to do with acceptability to view from work (during a free lunch period, for example), or at home around the kids.
#9 Eis on 08 Aug 2007 - 16:58
Maybe Opera should start having drunk pajama parties so they get as much attention as Firefox does.
#10 RangerLG on 08 Aug 2007 - 20:24
Quote -
Mozilla security chief Window Snyder


Am I the only one who finds it funny that the security chief for Mozilla is named Window?

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)