home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.sys.hp:9716 alt.security:4213
- Newsgroups: comp.sys.hp,alt.security
- Path: sparky!uunet!destroyer!fmsrl7!ef2007!bkelley
- From: bkelley@ef2007.efhd.ford.com (Brian Kelley)
- Subject: HP changes security related patch distribution policy
- Message-ID: <BtLo7J.8DB@ef2007.efhd.ford.com>
- Keywords: patch security HP
- Organization: Ford Motor Company
- Date: Wed, 26 Aug 1992 16:52:30 GMT
- Lines: 78
-
-
-
- On Tuesday August 11, I made the following post to comp.sys.hp and
- alt.security:
-
- >Some monthes ago we discovered a security problem with ftp on the RS/6000.
- >The fix was Very trivial. However, for some reason, it took many months
- >for a CERT advisory to appear. In this case, CERT didn't seem to work.
- >I did a little checking into the process. I learned that CERT won't issue
- >an advisory until a patch or work-around is available. On the RS/6000, it was
- >known from the start that a chmod on the ftp directory would correct the
- >problem. Regardless, my involvement with that particular bug was not direct
- >enough to be able to determine what actually caused the large delay.
- >
- >We recently discovered a rather serious security problem on the HP. We
- >reported the problem to HP on 6/10 and had a patch several days later. The
- >response from HP was very good. Ah, I thought - a chance to see how well
- >CERT really works. Initially, our patch was going to be a Ford "special" -
- >HP did not intend to release it to everyone. I felt that was not
- >appropriate. I indicated I would be contacting CERT and asked that the patch
- >receive a normal HP "patch ID". HP provided the patch IDs for the 300, 700
- >and 800 series (8.X only, as far as I know).
- >
- >I contacted CERT by phone and followed up with a very detailed Email message
- >on 6/24. That message described everything, gave the patch IDs and my call
- >reference number. CERT phoned and Emailed (again, detailed) their HP
- >contact person on 6/24. Very little progress seems to have been made.
- >Many calls have been made by CERT and things seem to be stalled on the HP
- >side.
- >
- >CERT is concerned about the availability of this patch. Normally, HP patches
- >are only available to software support customers. Before going public, CERT
- >would like to be sure these patches are available to Anyone with an HP
- >machine (just like Sun does). They are asking their HP contact to confirm
- >the availability of the patch. I am trying to find out who the HP
- >contact person is - I'd like to know the reason for the delay.
- >
- >What is the HP policy for distributing security related patches to HP
- >system owners without Software Support? Sun's policy is great - you don't
- >even have to rely on a potentially flaky local sales office. You just
- >call their 800 number, give your system serial number and ask for the patch.
- >
- > Brian
-
-
- Well, things are definitely looking good. CERT and myself have been pushing
- HP rather hard on this issue. HP has responded surprisingly quickly for
- such a large company. You can make a difference - just be persistent, and
- work for a big company ;-)
-
- HP is changing their policy regarding security related patches. They will
- be freely available to all HP system owners regardless of whether their
- machines are on software support.
-
- I'm told a new "security" section will be added to the HP support line
- system. You can connect to this system over the Internet or direct dial-in.
- High priority will be given to security related patches - they should appear
- in that section on a timely basis. HP says this section should be created
- within the next week or so.
-
- Expect a CERT advisory for this bug once the patch is freely available.
-
- Note that it does make some sense to have your machines on BasicLine support.
- The cost is about $40/month. No, I'm not suggesting that is inexpensive
- (especially for a home machine). Keep in mind HP's OS licensing policy.
- They support the current release and one release back. As I understand
- things, if you purchased your machine with 8.05, each machine you upgrade
- to 8.07 must have a BasicLine subscription. If you don't have BasicLine
- (or some other software support), you're not licensed to run any new
- OS versions. Not all vendors license this way.
-
- Brian
-
-
- ---
- bkelley@pms001.pms.ford.com
- Not speaking for Ford.
-
-