Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> What about the risk to the reputation of anyone who approves these patches?

This is a risk, but it's exposing vulnerabilities is always preferable to leaving them in place.

> Or of intentinally buggy patches making it into the wild and being exploited?

There was no real risk of this. They specifically did not allow it to make its way into real releases.

If they had allowed it into actual releases, I would have a serious problem with that.



There is also the risk that a third party sees the patch on a mailing list, and merges it to his internal branch because it looks like it is fixing one of his problem.

But I'd argue it is his own fault to use unsupported patches.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: