Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Pierre Joye
On Thu, Jul 15, 2010 at 4:27 AM, Larry Garfield wrote: > On Wednesday 14 July 2010 03:22:30 pm Dirk Haun wrote: >> Am 13.07.2010 um 17:12 Uhr schrieb Ferenc Kovacs: >> > it would be an interesting to check how many bugs were first marked as >> > bogus then re-opened and fixed. >> >> I've been wond

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Patrick ALLAERT
2010/7/14 Dirk Haun : > Am 13.07.2010 um 17:12 Uhr schrieb Ferenc Kovacs: > >> it would be an interesting to check how many bugs were first marked as >> bogus then re-opened and fixed. > > I've been wondering for a while now if much of the emotional reaction to bugs > being closed as "bogus" is du

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Adam Harvey
On 15 July 2010 04:22, Dirk Haun wrote: > Am 13.07.2010 um 17:12 Uhr schrieb Ferenc Kovacs: >> it would be an interesting to check how many bugs were first marked as >> bogus then re-opened and fixed. > > I've been wondering for a while now if much of the emotional reaction to bugs > being closed

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Larry Garfield
On Wednesday 14 July 2010 03:22:30 pm Dirk Haun wrote: > Am 13.07.2010 um 17:12 Uhr schrieb Ferenc Kovacs: > > it would be an interesting to check how many bugs were first marked as > > bogus then re-opened and fixed. > > I've been wondering for a while now if much of the emotional reaction to >

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Dirk Haun
Am 13.07.2010 um 17:12 Uhr schrieb Ferenc Kovacs: > it would be an interesting to check how many bugs were first marked as > bogus then re-opened and fixed. I've been wondering for a while now if much of the emotional reaction to bugs being closed as "bogus" is due to that very word. I mean, the

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Stas Malyshev
Hi! So waht will you tell me? That it is ok that anyone who did not make the change is closing something he do not understand until someone gets crazy about this? What we're trying to tell you is that there are tons of bug reports and way not enough people to triage them. And mistakes sometim

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Christian Schneider
Pierre Joye wrote: > On Wed, Jul 14, 2010 at 9:00 AM, Reindl Harald wrote: > >> No problem if you tell the other idiots which are thinking >> i should read the documentation that the should be quiet > > Stop to insult every second person on this list. You are not in the > Bahnhof Cafe here, some

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Pierre Joye
On Wed, Jul 14, 2010 at 9:00 AM, Reindl Harald wrote: > No problem if you tell the other idiots which are thinking > i should read the documentation that the should be quiet Stop to insult every second person on this list. You are not in the Bahnhof Cafe here, some respect is required, even if t

Re: [PHP-DEV] dangerous handling of security bugs

2010-07-14 Thread Reindl Harald
Am 14.07.2010 08:58, schrieb Rasmus Lerdorf: > On 7/13/10 11:53 PM, Reindl Harald wrote: >> Sorry but if the same webserver binary is running php5 with the same vhosts >> on the same machine and only one php-version does funny things why >> does anybody start a foolish discussion where the problem