Comment on Nginx core developer quits project in security dispute, starts “freenginx” fork

<- View Parent
JakenVeina@lemm.ee ⁨9⁩ ⁨months⁩ ago

There was another article I read that had a snippet from F5. As I read it, their concern was that they have two release tracks: the paid/subscription track, and the free track. They are actually the same code, but the free track is just 2 releases behind, so the idea is that if you want the “latest and greatest” stuff, you gotta pay. It’s a fairly common strategy in the industry.

So, the concern is that for security vulnerabilities that are not CVEs, info about the vulnerability (and how to exploit it) is out in the wild for two whole releases, before the patch reaches the free-tier users.

Seems like an actively good position on F5’s part, from this angle.

source
Sort:hotnewtop