Undisclosed hole in openssh on FreeBSD and Juniper?
11–20 of 47 posts
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#12 "Threads are for idiots."
At the time, I felt discounted and I was upset. I was younger then. Today, I realize what he meant and that he's right.Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#13Many years ago, I submitted a bug report to OpenBSD about an issue I had discovered with threads. I received a one line response from Theo. I still have the mail. He wrote: "Threads are for idiots." At the time, I felt discounted and I was upset. I was younger then. Today, I realize what he meant and that he's right.
Could you please expand on this?
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#14But it should be noted that this guy has a relatively rocky history with *BSD, and his nearly context-free, ambiguous trash-talking of FreeBSD should be taken with a grain of salt.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#15What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix? It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.
OpenSSL is an encryption API maintained by an entirely different group of people.
EDIT: Modified my reply. OpenSSH at some point moved it's "restrictively licenced software" (RSA, DES, etc) out of it's codebase and now depends on OpenSSL according to it's license. http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/LICENC...
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#16Earlier quoted context omitted.
It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix? It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.
OpenSSH is a SSH client and server provided by the Open BSD Foundation. OpenSSL is an encryption API maintained by an entirely different group of people. EDIT: Modified my reply. OpenSSH at some point moved it's "restrictively licenced software" (RSA, DES, etc) out of it's codebase and now depends on OpenSSL according to it's license. http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/LICENC...
It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSH consumers - only when they have a fix?
It could be best fixed in OpenSSH itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#17Earlier quoted context omitted.
It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix? It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.
OpenSSH is a SSH client and server provided by the Open BSD Foundation. OpenSSL is an encryption API maintained by an entirely different group of people. EDIT: Modified my reply. OpenSSH at some point moved it's "restrictively licenced software" (RSA, DES, etc) out of it's codebase and now depends on OpenSSL according to it's license. http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/LICENC...
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#18What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#19What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
Long Answer: It's complicated and I do not understand the whole picture myself.
I can however outline two things that likely exasperate the situation.
a) OpenSSH is used by nearly everyone. Nearly every unix-like installation includes a copy of OpenSSH. Most companies which do business on the internet use a unix-like operating system in some way.
The OpenBSD Foundation has had trouble obtaining funding to cover operating costs in the past. Included in these operating costs is support and auditing of OpenSSH.
b) There has been a long and colored history between FreeBSD and OpenBSD. A lot of code and features developed under OpenBSD has been ported over to FreeBSD such as the OpenBSD Packet Filter (PF).
Juniper uses FreeBSD and PF in their routers and have donated in various ways to FreeBSD. For example, Juniper donated three EX3200s with full contracts to FreeBSD for use in their datacenter.
The OpenBSD Foundation on the other hand has not really seen the same support.
Re: Undisclosed hole in openssh on FreeBSD and Juniper?
#20What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.
Short Answer: Bitterness. Long Answer: It's complicated and I do not understand the whole picture myself. I can however outline two things that likely exasperate the situation. a) OpenSSH is used by nearly everyone. Nearly every unix-like installation includes a copy of OpenSSH. Most companies which do business on the internet use a unix-like operating system in some way. The OpenBSD Foundation has had trouble obtain…
Just dropping that hint is ambiguous drama baiting.