On Thu, 05 Feb 2004 14:56:13 EST, "Steven M. Bellovin" said: > Why is that bad? I have no objection to giving vendors a reasonable > amount of time to fix problems before announcing the whole. Or is your > point that two days hardly seems like enough time to develop -- and > *test* -- a fix?
Two days is plenty if it's a Homer Simpson-esque "D'Oh!" bug. Probably not if it's something that requires some regression testing.
pgp00000.pgp
Description: PGP signature