Live data from Hacker News

Some thoughts on security after ten years of Qmail 1.0

blog.acolyer.org

121–123 of 123 posts

Re: Some thoughts on security after ten years of Qmail 1.0

#121

Earlier quoted context omitted.

"qmail itself is so feature-poor that traditionally, nobody was and is actually running qmail. Instead everybody is running "qmail" which is qmail plus some patches." I ran and continue to run qmail without any patches. The above quoted statements thus cannot be true. But maybe "nobody" and "everybody" are figures of speech?

So...are you running an open SMTP relay, or are you refusing to relay mail for your own users? Because I'm pretty sure that with an unpatched qmail, you've got to be doing one or the other. Also, how are you dealing with backscatter?

Not using qmail the way you are (incorrectly) assuming.

I am an end user not an email provider.

For example I use qmail to provide "inter-device email" on a local network of devices all belonging to the same user, and not connected to the internet. Not that I love email but these devices are sometimes "locked down" by default and email is one of the few ways to move files between devices without using the internet.

Another example is using qmail on a tap-based layer 2 overlay (not OpenVPN) to provide encrypted "peer-to-peer email". Each peer is running qmail-smtpd bound to a tap device. This was an experiment to prove encrypted email is easy.

qmail running under curvecpserver is another experiment.

Re: Some thoughts on security after ten years of Qmail 1.0

#122

Earlier quoted context omitted.

"qmail itself is so feature-poor that traditionally, nobody was and is actually running qmail. Instead everybody is running "qmail" which is qmail plus some patches." I ran and continue to run qmail without any patches. The above quoted statements thus cannot be true. But maybe "nobody" and "everybody" are figures of speech?

qmail won't even compile on modern glibc without the errno patches - you must have at least some patching done.

Not using glibc.1

Not using Linux.

Advice for all commenters who make presumptions about others computer use: Please kindly check your assumptions.

1 Is this an issue for musl and the various other alternatives to glibc? I have no idea but seems like only referring to glibc 2.3.x and up is a bit myopic. Its possible some users might not be using that library. I am one such user.

Re: Some thoughts on security after ten years of Qmail 1.0

#123
post #39

Earlier quoted context omitted.

Which part. The model? The article explained it well enough. I think of it as two main parts: (1) make fewer bugs, and (2) show your users the correct way to do things (which is the inverse of getting the correct requirements). Or are you asking what took me fifteen years to understand? Dan basically planned the whole thing. When the whole thing was too big, he would break off a piece that wasn't and develop it as a…

> learning how to read and write dense code > and that's what I learned how to do This is good code? for(i=b=0;i t){r0(a);poop(f);R 0;}writer(f,kC(a),a->n);r0(a);if(!w)close(f);}if(b==r)R 1;q=0;o=0;a=ktn(11,0),v=ktn(0,0);}else{if((c-m)==10&& !strncasecmp(p+m,"connection",c-m))cf=p[s];js(&a,sn(p+m,c-m));jk(&v,kpn(p+s,e-s));}w=e=g=s=c=0;m=i+1;break; case' ':case'\t':case'\r':if(w&&!g)g=i;if(s==(e=i))++s;break; case':':…

That's how people with an APL background write C and it is, in fact, readable to those people: to me, however, it's gibberish
Post reply on HN