Mozilla and Security

Tuesday March 28th, 2000

Nothing like a little rhetoric to get you hopping in the morning. This latest comes from some guy called AP who made a submission to Slashdot regarding a discussion currently going on in In it, he states that the Mozilla team is contemplating limiting access to security bugs, implying that the team is substituting obscurity for security. He fans the flames by saying "Are Mozilla developers missing the point of open source (implying open security bugs) or are they under pressure from Netscape?"

If you read the discussion thread titled "Security bugs and disclosure" in, you will see that the discussion is not exactly what AP portrayed, and members are actually having a serious discussion about disclosure, security and Open Source. This is what Open Source is about, people!!! What kind of access would you have to this kind of discussion if the process was closed? Open Source isn't just about open code - it's about open discussion, as well. And has provided ample opportunity for discussion regarding practically every level of the development process. I think the fact that AP came across this discussion at all proves that the discussion process is adequately open.

If you have opinions regarding this, you should feel free to post them in the security newsgroup, but please read the previous posts in the thread, because they are reasonable posts from people who are trying to do the right thing.

#7 You don't need a schematic to slash a tire

by rmarian

Tuesday March 28th, 2000 1:33 PM

You are replying to this message

Some people don't get it. Cracking is easy. Always will be. If you can think in complete sentences and paragraphs you can crack.

And as for the revealing of bugs: If you couldn't describe the bug you couldn't know it exists. Therefore your assumption that few people could understand the issues is false. If you present the bug, qualified people will understand it. How many Mozilla no-developers would download the code in the first place? Thge code is 20MBs the binary only 5-7MBs. It doesn't make sense to not disclose.

Why do you assume the population is made of incompetent FOX potatoes?

Open Source is Open Hardware applied to software. Why is that so hard to understand?