<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Bug fix scorecard</title>
	<atom:link href="http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/feed/" rel="self" type="application/rss+xml" />
	<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 05 Mar 2009 04:54:12 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Security Spin Cycles - The Capslock Assassin</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1068</link>
		<dc:creator>Security Spin Cycles - The Capslock Assassin</dc:creator>
		<pubDate>Wed, 17 Oct 2007 02:34:27 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1068</guid>
		<description>[...] Jeff Jones posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their &#8220;Truth Happens&#8221; blog back in August, which itself quotes a post on Lxer.com. [...]</description>
		<content:encoded><![CDATA[<p>[...] Jeff Jones posted a blog entry to celebrate Red Hat fixing their 1000th unique security vulnerability.  He also draws attention to a Red Hat post on their &#8220;Truth Happens&#8221; blog back in August, which itself quotes a post on Lxer.com. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Ryder</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1067</link>
		<dc:creator>Mark Ryder</dc:creator>
		<pubDate>Wed, 17 Oct 2007 01:09:04 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1067</guid>
		<description>You guys are amazing, thinking that fixing more bugs is a good thing. What are you doing to reduce the number of security bugs in the first? Shipping junk, and fixing lots of bugs later is simply &quot;cowboy coding&quot; and nothing to be proud of.</description>
		<content:encoded><![CDATA[<p>You guys are amazing, thinking that fixing more bugs is a good thing. What are you doing to reduce the number of security bugs in the first? Shipping junk, and fixing lots of bugs later is simply &#8220;cowboy coding&#8221; and nothing to be proud of.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: totalnetsolutions.net &#187; Microsoft VS. Red Hat - Why did they go there?</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1066</link>
		<dc:creator>totalnetsolutions.net &#187; Microsoft VS. Red Hat - Why did they go there?</dc:creator>
		<pubDate>Tue, 16 Oct 2007 19:45:09 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1066</guid>
		<description>[...] I saw this post from Jeff Jones over at Microsoft today. He mentions that Red Hat Enterprise Linux 4 recently patched their 1000th vulnerability, and provides a quote from Truth Happens(direct link to post), which is a Red Hat blog. I suggest you at least read Jeff&#8217;s post, since he quotes the relevant point of the Truth article. [...]</description>
		<content:encoded><![CDATA[<p>[...] I saw this post from Jeff Jones over at Microsoft today. He mentions that Red Hat Enterprise Linux 4 recently patched their 1000th vulnerability, and provides a quote from Truth Happens(direct link to post), which is a Red Hat blog. I suggest you at least read Jeff&#8217;s post, since he quotes the relevant point of the Truth article. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wilsonz</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1065</link>
		<dc:creator>Wilsonz</dc:creator>
		<pubDate>Tue, 18 Sep 2007 21:04:45 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1065</guid>
		<description>This post looks like FUD to me or at least its a great example statistics published in an incomplete manner. The same data published as a ratio of fixes by category to bugs found would tell the story more accurately. Maddog&#039;s post addresses the other reason this comparison is likely invalid.</description>
		<content:encoded><![CDATA[<p>This post looks like FUD to me or at least its a great example statistics published in an incomplete manner. The same data published as a ratio of fixes by category to bugs found would tell the story more accurately. Maddog&#8217;s post addresses the other reason this comparison is likely invalid.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maddog</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1064</link>
		<dc:creator>Maddog</dc:creator>
		<pubDate>Tue, 28 Aug 2007 05:03:44 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1064</guid>
		<description>Vista not having much to fix? Or isn&#039;t it more like they don&#039;t announce everything they try to fix? Microsoft has a history of not disclosing bugfixes (see &quot;Skeletons in Microsoft’s Patch Day closet&quot;; http://blogs.zdnet.com/security/?p=316) and this controversial practice will definitely skew Jeff&#039;s numbers. That renders Jeff&#039;s &quot;scorecard&quot; practically useless.</description>
		<content:encoded><![CDATA[<p>Vista not having much to fix? Or isn&#8217;t it more like they don&#8217;t announce everything they try to fix? Microsoft has a history of not disclosing bugfixes (see &#8220;Skeletons in Microsoft’s Patch Day closet&#8221;; <a href="http://blogs.zdnet.com/security/?p=316)" rel="nofollow">http://blogs.zdnet.com/security/?p=316)</a> and this controversial practice will definitely skew Jeff&#8217;s numbers. That renders Jeff&#8217;s &#8220;scorecard&#8221; practically useless.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1063</link>
		<dc:creator>Alan</dc:creator>
		<pubDate>Sat, 25 Aug 2007 03:04:24 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1063</guid>
		<description>Ummm.  So since Red Hat had more vilnerabilities than Microsoft, they did a better job??  That&#039;s the way to spin it.  :)

Now if they had the same vulnerabilities discovered and one fixed more than the other, then that is a win.  Otherwise Windows Vista is the clear winner here for not having much to fix.</description>
		<content:encoded><![CDATA[<p>Ummm.  So since Red Hat had more vilnerabilities than Microsoft, they did a better job??  That&#8217;s the way to spin it.  <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Now if they had the same vulnerabilities discovered and one fixed more than the other, then that is a win.  Otherwise Windows Vista is the clear winner here for not having much to fix.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1062</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Fri, 24 Aug 2007 21:59:06 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1062</guid>
		<description>So, uh, is Microsoft&#039;s numbers so low because substantially fewer vulnerabilities were discovered, or was it because they are slow to fix things.  From other posts on Jeff&#039;s blog concerning days of vulnerability, MS also comes out in the lead, suggesting that they are fixing the bugs as they arise rather than avoiding fixes.

Also, isn&#039;t it a bit misleading to suggest that Red Hat, with 1/40th the employees is actually fixing all of those vulnerabilities.  I mean, shouldn&#039;t some credit go to the FOSS community that also contributes to fixing vulnerabilities rather than giving redhat all of the credit.</description>
		<content:encoded><![CDATA[<p>So, uh, is Microsoft&#8217;s numbers so low because substantially fewer vulnerabilities were discovered, or was it because they are slow to fix things.  From other posts on Jeff&#8217;s blog concerning days of vulnerability, MS also comes out in the lead, suggesting that they are fixing the bugs as they arise rather than avoiding fixes.</p>
<p>Also, isn&#8217;t it a bit misleading to suggest that Red Hat, with 1/40th the employees is actually fixing all of those vulnerabilities.  I mean, shouldn&#8217;t some credit go to the FOSS community that also contributes to fixing vulnerabilities rather than giving redhat all of the credit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maddog</title>
		<link>http://truthhappens.redhat.com/2007/08/22/bug-fix-scorecard/#comment-1061</link>
		<dc:creator>Maddog</dc:creator>
		<pubDate>Thu, 23 Aug 2007 08:30:44 +0000</pubDate>
		<guid isPermaLink="false">http://truthhappens.redhatmagazine.com/2007/08/22/bug-fix-scorecard/#comment-1061</guid>
		<description>Excellent reverse spin on Microsoft&#039;s data! This just goes to show that Microsoft is spinning data to make its products look good. Jeff Jones should stop pretending he&#039;s a security guy and proclaim himself as Microsoft&#039;s marketing guru, their UberFUDMeister!</description>
		<content:encoded><![CDATA[<p>Excellent reverse spin on Microsoft&#8217;s data! This just goes to show that Microsoft is spinning data to make its products look good. Jeff Jones should stop pretending he&#8217;s a security guy and proclaim himself as Microsoft&#8217;s marketing guru, their UberFUDMeister!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
