<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Adobe Reader bug info: Better late than never, huh?</title>
	<atom:link href="http://www.teleread.org/blog/2008/05/08/adobe-reader-bug-info-better-late-than-never-huh/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.teleread.org/blog/2008/05/08/adobe-reader-bug-info-better-late-than-never-huh/</link>
	<description>News &#38; views on e-books, libraries, publishing and related topics</description>
	<pubDate>Sun, 06 Jul 2008 00:39:19 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: David Rothman</title>
		<link>http://www.teleread.org/blog/2008/05/08/adobe-reader-bug-info-better-late-than-never-huh/#comment-791669</link>
		<dc:creator>David Rothman</dc:creator>
		<pubDate>Thu, 08 May 2008 18:02:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.teleread.org/blog/2008/05/08/adobe-reader-bug-info-better-late-than-never-huh/#comment-791669</guid>
		<description>Big thanks for at least unofficially giving Adobe's side, John. That's a helpful response. I'm gong to take the liberty of reproing in full your note to CW. David

Timing of releases
Submitted by John Dowdell on May 7, 2008 - 14:59.

Hi Gregg, I'd defer to members of Adobe's security team for full details, but usually we don't provide additional info about the nature of an exploit until all versions are updated.

The Acrobat 8.x series was updated awhile ago, but today the Acrobat 7.x series was also updated, for those intranets which have slow approval cycles for new major versions.

(This practice also gives a significant number of consumers a chance to get protected, before providing background info to security researchers which might incidentally help criminals.)

jd/adobe</description>
		<content:encoded><![CDATA[<p>Big thanks for at least unofficially giving Adobe&#8217;s side, John. That&#8217;s a helpful response. I&#8217;m gong to take the liberty of reproing in full your note to CW. David</p>
<p>Timing of releases<br />
Submitted by John Dowdell on May 7, 2008 - 14:59.</p>
<p>Hi Gregg, I&#8217;d defer to members of Adobe&#8217;s security team for full details, but usually we don&#8217;t provide additional info about the nature of an exploit until all versions are updated.</p>
<p>The Acrobat 8.x series was updated awhile ago, but today the Acrobat 7.x series was also updated, for those intranets which have slow approval cycles for new major versions.</p>
<p>(This practice also gives a significant number of consumers a chance to get protected, before providing background info to security researchers which might incidentally help criminals.)</p>
<p>jd/adobe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Dowdell</title>
		<link>http://www.teleread.org/blog/2008/05/08/adobe-reader-bug-info-better-late-than-never-huh/#comment-791581</link>
		<dc:creator>John Dowdell</dc:creator>
		<pubDate>Thu, 08 May 2008 16:08:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.teleread.org/blog/2008/05/08/adobe-reader-bug-info-better-late-than-never-huh/#comment-791581</guid>
		<description>Hi David, I left a comment at Gregg's piece pretty much as soon as it was published -- the comment was printed, thank goodness, but at the bottom of the page, where it was easy to miss.

Adobe Reader 8.x was released pretty quickly. But details of what it fixed were not published until after we had older versions updated too. (Sometimes an intranet will approve minor versions on a shorter cycle than they will major versions, and so we need to go back and update older codebases as well.)

So the answer to Gregg's implicit question of "Why did it take so long to learn juicy details of badguy practices?" would be something like "To give current users a meaningful chance to update first, and also to take care of people who cannot use the current version."

Good?

jd/adobe</description>
		<content:encoded><![CDATA[<p>Hi David, I left a comment at Gregg&#8217;s piece pretty much as soon as it was published &#8212; the comment was printed, thank goodness, but at the bottom of the page, where it was easy to miss.</p>
<p>Adobe Reader 8.x was released pretty quickly. But details of what it fixed were not published until after we had older versions updated too. (Sometimes an intranet will approve minor versions on a shorter cycle than they will major versions, and so we need to go back and update older codebases as well.)</p>
<p>So the answer to Gregg&#8217;s implicit question of &#8220;Why did it take so long to learn juicy details of badguy practices?&#8221; would be something like &#8220;To give current users a meaningful chance to update first, and also to take care of people who cannot use the current version.&#8221;</p>
<p>Good?</p>
<p>jd/adobe</p>
]]></content:encoded>
	</item>
</channel>
</rss>
