Looking at the dates, this bug was fixed in under a month. Did the buggy code really get released to production environments that fast? A priori unlikely IMO, which means this "vulnerability" is instead just the normal development process at work. I'm sure we've all committed code with mindbogglingly dumb bugs at one point or another.
Security Fix in Open BSD
21–30 of 36 posts
Re: Security Fix in Open BSD
#22Earlier quoted context omitted.
de Raadt: "We've been auditing since the mail came in! We have already found two bugs in our cryptographic code. We are assessing the impact." http://www.itwire.com/opinion-and-analysis/open-sauce/43995-... "Until 2 days ago I had no idea that both Jason and Angelos in the past did work for a company that does that business"
There is no way Theo didn't know Jason worked at NETSEC; Jason's a co-author of an academic paper about the OpenBSD cryptography implementation, under a NETSEC address.
Re: Security Fix in Open BSD
#23Looking at the dates, this bug was fixed in under a month. Did the buggy code really get released to production environments that fast? A priori unlikely IMO, which means this "vulnerability" is instead just the normal development process at work. I'm sure we've all committed code with mindbogglingly dumb bugs at one point or another.
A month? I'm getting over a year from my look; the bug was introduced with the original feature in 2001.
Re: Security Fix in Open BSD
#24In 2001, Angelos Keromytis --- then a grad student at Penn, now a Columbia professor --- added support for hardware-accelerated IPSEC NICs. When you have an IPSEC NIC, the channel between the NIC and the IPSEC stack keeps state to tell the stack not to bother doing the things the NIC already did, among them validating the IPSEC ESP authenticator. Angelos' code had a bug; it appears to have done the software check onl…
> It's interesting that the bug was fixed without an advisory (oh to be a fly on the wall on ICB that day; Theo had a, um, a, "way" with his dev team). This would be my question. That seemingly small change has large security implications since it means that branch was disabled on certain erroneous conditions for some extended period of time and then silently changed back. I think you're right that Jason fixed it, bu…
It's unlikely that NETSEC would have had any management influence over Angelos during that work.
Re: Security Fix in Open BSD
#25In 2001, Angelos Keromytis --- then a grad student at Penn, now a Columbia professor --- added support for hardware-accelerated IPSEC NICs. When you have an IPSEC NIC, the channel between the NIC and the IPSEC stack keeps state to tell the stack not to bother doing the things the NIC already did, among them validating the IPSEC ESP authenticator. Angelos' code had a bug; it appears to have done the software check onl…
for what it's worth (not much), angelos also contracted for netsec.
Re: Security Fix in Open BSD
#26Earlier quoted context omitted.
There is no way Theo didn't know Jason worked at NETSEC; Jason's a co-author of an academic paper about the OpenBSD cryptography implementation, under a NETSEC address.
yep, you can see this post from 2000. http://monkey.org/openbsd/archive/misc/0004/msg00583.html
Re: Security Fix in Open BSD
#27Earlier quoted context omitted.
de Raadt: "We've been auditing since the mail came in! We have already found two bugs in our cryptographic code. We are assessing the impact." http://www.itwire.com/opinion-and-analysis/open-sauce/43995-... "Until 2 days ago I had no idea that both Jason and Angelos in the past did work for a company that does that business"
There is no way Theo didn't know Jason worked at NETSEC; Jason's a co-author of an academic paper about the OpenBSD cryptography implementation, under a NETSEC address.
What the company did is surprising, not who worked there.
Re: Security Fix in Open BSD
#28Earlier quoted context omitted.
There is no way Theo didn't know Jason worked at NETSEC; Jason's a co-author of an academic paper about the OpenBSD cryptography implementation, under a NETSEC address.
rest of quote: "And it is true, wow, that company really was in that business! Now they (the company) belong to Verizon." What the company did is surprising, not who worked there.
Re: Security Fix in Open BSD
#29Earlier quoted context omitted.
rest of quote: "And it is true, wow, that company really was in that business! Now they (the company) belong to Verizon." What the company did is surprising, not who worked there.
I assume you mean "what the company is alleged, by one guy, to have done".