Live data from Hacker News

Undisclosed hole in openssh on FreeBSD and Juniper?

thread.gmane.org

1–10 of 47 posts

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#5
What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure....

1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience.

2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#6

If I parse Theo correctly, he clearly says that FreeBSD does have a hole. Its really really hard to imagine he is lying.

I'm guessing it is of modest severity, if they even feel they can _get away_ with keeping it to themselves. But its still deeply troubling.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#7
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

> Government gag order

I can't imagine a government gag order that allows you to publicly hint that there's a problem.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#8
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

It's not a good reason that they aren't disclosing, it's a personal reason.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#9
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix?

It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.

Post reply on HN