Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Debian OpenSSL critical security bug
- Date: Wed, 14 May 2008 08:27:53 +0900
- From: Curt Sampson <cjs@example.com>
- Subject: Re: [tlug] Debian OpenSSL critical security bug
- References: <4fefd6340805131436p641e9605k84954b75accb8e2e@mail.gmail.com> <d8fcc0800805131552g4d1d0324me48d16a82980af33@mail.gmail.com>
- User-agent: Mutt/1.5.17 (2007-11-01)
On 2008-05-14 07:52 +0900 (Wed), Josh Glover wrote: > The lesson here is that distros should not add patches to upstream > sources that made fundamental changes. Actually, the lesson is that distros shouldn't touch security-related code at all, and possibly also expand their definition of what is "security-related" to include everything in the random-number generation chain, among other things. I strongly suspect that this change appeared to the Debian maintainers not to be any kind of fundemental change. In the security world, it can be very hard to tell what is and isn't fundemental; remember the story about the NSA's changes to the S-box arrangement of the DES algorithm. cjs -- Curt Sampson <cjs@example.com> +81 90 7737 2974 Mobile sites and software consulting: http://www.starling-software.com
- Follow-Ups:
- Re: [tlug] Debian OpenSSL critical security bug
- From: Josh Glover
- Re: [tlug] Debian OpenSSL critical security bug
- From: Edward Middleton
- References:
- [tlug] Debian OpenSSL critical security bug
- From: Gernot Hassenpflug
- Re: [tlug] Debian OpenSSL critical security bug
- From: Josh Glover
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] [off topic] religion and the internet in Japan
- Next by Date: [tlug] Nominations for Sourceforge.net Community Choice Awards Now Open
- Previous by thread: Re: [tlug] Debian OpenSSL critical security bug
- Next by thread: Re: [tlug] Debian OpenSSL critical security bug
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links