Live data from Hacker News

Merry Christmas from the FreeBSD Security Team

lists.freebsd.org

21–24 of 24 posts

Re: Merry Christmas from the FreeBSD Security Team

#21

Earlier quoted context omitted.

Nonsense. People stick with telnet because of ignorance. That is why you remove telnetd, and force them to update. There is no difficulty in switching, and thus no valid reason not to switch.

As an example, there are entire classes of embedded platforms that support networking but barely have enough RAM even for the IP stack. Is it really sensible to add $10 to the cost of a temperature sensor just so it has enough RAM and CPU to handle SSH?

This is the piece that allows you to telnet /into/ a new shiny FreeBSD box, for which there are no legitimate uses in 2011.

If they take this bit out, you can still telnet out to your embedded hardware, L2 switches, and the like.

Re: Merry Christmas from the FreeBSD Security Team

#22
post #12

Could you add something to the title explaining what this is about? maybe (Telnet remote root vulnerability) or something like that

It seemed to me that "Merry Christmas" was a good way of covering "look at the 5 presents we just sent you".

I think you risk people skipping over the message without reading the contents, because the title will make them think it's an empty 'happy holidays' message and not a vulnerability advisory...

Re: Merry Christmas from the FreeBSD Security Team

#23

Earlier quoted context omitted.

It seemed to me that "Merry Christmas" was a good way of covering "look at the 5 presents we just sent you".

I think you risk people skipping over the message without reading the contents, because the title will make them think it's an empty 'happy holidays' message and not a vulnerability advisory...

That email went to lists which also had 5 vulnerability announcements arrive in the preceding minutes. It was an extra communiqué, not a replacement for the normal advisories.

Re: Merry Christmas from the FreeBSD Security Team

#24

Earlier quoted context omitted.

It seemed to me that "Merry Christmas" was a good way of covering "look at the 5 presents we just sent you".

I think you risk people skipping over the message without reading the contents, because the title will make them think it's an empty 'happy holidays' message and not a vulnerability advisory...

I was thinking that at first, then I got curious why a 'happy holidays' message was on HN.
Post reply on HN