Live data from Hacker News

Security Fix in Open BSD

code.bsd64.org

31–36 of 36 posts

Re: Security Fix in Open BSD

#31

I presume you are attempting to imply that this one of the 'leet' FBI backdoors that the Perry email discussed. It would help if you actually said why you thought this patch was interesting when submitting it to HN. I hope we are not going to get a rash of inarticulate HN submissions for every minor patch to openbsd which may have security implications. I doubt this is in anyway related to the recent drama. The initi…

  > I hope we are not going to get a rash of inarticulate
  > HN submissions for every minor patch to openbsd which
  > may have security implications.
I do. Submissions are cheap and skippable. Plus, now I get to look at all these small bugs and not make the same mistakes in my own code, which is both a huge win in my book and something that one can't learn from a textbook.

Re: Security Fix in Open BSD

#32
post #19
post #15

Earlier quoted context omitted.

The most worrying thing about it is probably just that it took a year to notice - you would think "throw a forged authenticator at it" would be in the regression tests for an IPSEC implementation.

"Regression tests for an IPSEC implementation". Heh.

lol.. are there any tests at all..

Re: Security Fix in Open BSD

#33
post #31

I presume you are attempting to imply that this one of the 'leet' FBI backdoors that the Perry email discussed. It would help if you actually said why you thought this patch was interesting when submitting it to HN. I hope we are not going to get a rash of inarticulate HN submissions for every minor patch to openbsd which may have security implications. I doubt this is in anyway related to the recent drama. The initi…

> I hope we are not going to get a rash of inarticulate > HN submissions for every minor patch to openbsd which > may have security implications. I do. Submissions are cheap and skippable. Plus, now I get to look at all these small bugs and not make the same mistakes in my own code, which is both a huge win in my book and something that one can't learn from a textbook.

This submission prior to tptacek's (rather good) analysis was of little value. The original submitter gave absolutely no context to the diff.

I don't think we can depend on tptacek always being on hand.

This bug itself is not novel and something any programmer (if they are being honest) will admit to doing themselves.

The really interesting part of this story is not technical at all (and not evident from the posted patch) - why did the openbsd team not feel it necessary to release a security advisory for this bug. That decision may tarnish their reputation more than any wild conspiracy claims.

Re: Security Fix in Open BSD

#34
post #31

I presume you are attempting to imply that this one of the 'leet' FBI backdoors that the Perry email discussed. It would help if you actually said why you thought this patch was interesting when submitting it to HN. I hope we are not going to get a rash of inarticulate HN submissions for every minor patch to openbsd which may have security implications. I doubt this is in anyway related to the recent drama. The initi…

> I hope we are not going to get a rash of inarticulate > HN submissions for every minor patch to openbsd which > may have security implications. I do. Submissions are cheap and skippable. Plus, now I get to look at all these small bugs and not make the same mistakes in my own code, which is both a huge win in my book and something that one can't learn from a textbook.

"Submissions are cheap and skippable."

By that logic, you will not mind if I spam your mailbox since emails are cheap and skippable.

Re: Security Fix in Open BSD

#35

I presume you are attempting to imply that this one of the 'leet' FBI backdoors that the Perry email discussed. It would help if you actually said why you thought this patch was interesting when submitting it to HN. I hope we are not going to get a rash of inarticulate HN submissions for every minor patch to openbsd which may have security implications. I doubt this is in anyway related to the recent drama. The initi…

Angelos has (had?) an email address from the University of Crete (now uoc.gr, formerly uch.gr), of which he's a graduate.

Nothing weird there.

Re: Security Fix in Open BSD

#36
post #31

Earlier quoted context omitted.

> I hope we are not going to get a rash of inarticulate > HN submissions for every minor patch to openbsd which > may have security implications. I do. Submissions are cheap and skippable. Plus, now I get to look at all these small bugs and not make the same mistakes in my own code, which is both a huge win in my book and something that one can't learn from a textbook.

This submission prior to tptacek's (rather good) analysis was of little value. The original submitter gave absolutely no context to the diff. I don't think we can depend on tptacek always being on hand. This bug itself is not novel and something any programmer (if they are being honest) will admit to doing themselves. The really interesting part of this story is not technical at all (and not evident from the posted p…

The submitter works about 15 away from me, for what it's worth.
Post reply on HN