Comment Re:Untrustworthy is an Understatement (Score 1) 21
They patched it rapidly only to have a very similar vulnerability affecting the very same components drop like a day later.
Arguably the patching effort lacked real analysis, that should have been triggered, and got pushed out with the first obvious fix applied. On the other hand leaving users with only the option to implement a workaround that disables ipsec while a full fix is investigated, is also a problem...
I am not criticizing anyone here, disclosure vs time to patch, and regression avoidance in complex software systems is a difficult problem. While it speaks to things like code quality and security priority, I don't think when it comes to large software projects you can really charaterize either of those things with a methodolgy that amounts SELECT COUNT(*) FROM cve WHERE project =