full-disclosure flamewar
Tuesday, 28. November 2006, 02:06:34
Oops, I managed to start a flame-war on the full-discosure mailing list. 
I wrongly attributed to malice an inexperienced attempt at programming, and the poster simply exploded with insults. He was attempting to solve the minor issue of log-noise from weak password scans, but in doing so replaced it with a much more serious remote pre-authentication root vulnerabliity.
Eventually he understood the issue and we took the discussion off-list, he's made an attempt to fix it although it still looks rather fragile.
I wrongly attributed to malice an inexperienced attempt at programming, and the poster simply exploded with insults. He was attempting to solve the minor issue of log-noise from weak password scans, but in doing so replaced it with a much more serious remote pre-authentication root vulnerabliity.
Eventually he understood the issue and we took the discussion off-list, he's made an attempt to fix it although it still looks rather fragile.