Yes, this is wasteful, but what else could the IRS have done without approval from congress?
[0] http://www.reuters.com/article/2013/03/23/us-usa-fiscal-budg...
Yes, this is wasteful, but what else could the IRS have done without approval from congress?
[0] http://www.reuters.com/article/2013/03/23/us-usa-fiscal-budg...
Oooops. So much for your talking point.
Go away, troll.
Patching the security issues themselves? I know this can be complex in many cases but the security and reverse engineering community have this knowledge, probably not fixing the whole issue but at least blocking it.
I've wrote an article about doing this here: http://blog.nektra.com/main/2013/08/07/using-deviare-to-crea... last year.
You wouldn't want someone downloading random patches off the Internet or hiring a non-MS employee to make a patch without hiring multiple people to verify the integrity and usefulness of the patch (think backdoor) to fix computers handling your tax information. Do you?
I wouldn't.
You wouldn't download a random patch for heartbleed until openssl releases the official notice and patch. Or you won't download because you want the fix from your distro vendor.
Yes. At the end it's all about trust.
With a good community making hotpatches, and explaining their fixes I will install them.
If they just pull patches from the community themselves, when something goes wrong they will have to take the blame themselves and people will think they are foolish being so reckless. As a techie, this option may seem feasible to you but then again you're just some random guy on HN who probably thinks node.js is the be all and end all of IT. I doubt you've got the intelligence (cleary) or the experience (very cleary) to understand how the IT industry works at a human, risk management and legal level.
No, my company sells hard core technology to big vendors and sign the kind of corporate contracts that you refer in your comment. Since the IRS will not solve the issue there is another route: selling a hotpatch service to another vendor who sells to the IRS.
You will have to be reassure that your patch will work and is risk free. If not, get ready for a bill and possibly a congressional hearing.
Good community is great, but you need to shift responsibility whenever possible. Not that there aren't any kernel hackers work in the public service sector, but they have other important things to do than fixing someone else' product if there's a choice.
No, they're paying $11M so they can say "We paid Microsoft $11M! What else could we possibly do?" when something goes wrong.