Re: De Raadt + FBSD + OpenSSH + hole?

看板FB_security作者時間11年前 (2014/04/14 20:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串4/29 (看更多)
On Mon, 14 Apr 2014 01:38:40 +0300 Todor Todorov <todorov@paladin.bulgarpress.com> wrote: > Oh now I sense some angst. Please ask Kirk McKusick, he knows the > story about why this is not being disclosed to FreeBSD. Sometimes I > feel a bit sorry for them (and for him), but then the next minute I > don't feel sorry because there's damn good reasons they won't be > told about what I found. My first thought when I saw this was "ego over ethics," which says more about Theo than FreeBSD. *If* there's an issue it'll come out eventually regardless of any little games the pseudo-deities wish to play. In the meantime, follow best practice, lock down your SSH, use keys rather than passwords, password protect the private key, ensure that only trusted people who need it get shell access and disable anything that isn't absolutely necessary. -- Safer alternative to smoking under threat from over-regulation due to pseudo-science and puritanism. Please help keep personal vapourisers available for ex and potential ex-smokers at http://www.efvi.eu/ by showing your support for this citizens' initiative. _______________________________________________ freebsd-security@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
文章代碼(AID): #1JIzL3Pw (FB_security)
討論串 (同標題文章)
文章代碼(AID): #1JIzL3Pw (FB_security)