Undisclosed hole in openssh on FreeBSD and Juniper?
thread.gmane.org
Undisclosed hole in openssh on FreeBSD and Juniper?
1–10 of 47 posts
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#2Previously: https://news.ycombinator.com/item?id=7568059
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#3Its really really hard to imagine he is lying.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#4Could someone please explain this?
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#51. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience.
2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#6If I parse Theo correctly, he clearly says that FreeBSD does have a hole. Its really really hard to imagine he is lying.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#7What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
I can't imagine a government gag order that allows you to publicly hint that there's a problem.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#8What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#9What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#10> Please ask Kirk McKusick, he knows the story about why this is not being disclosed to FreeBSD Could someone please explain this?