Theo de Raadt on OpenSSH security flaws
Posted Mar 29, 2006 13:09 UTC (Wed) by
jmtapio (guest, #23124)
Parent article:
Interview: Theo de Raadt of OpenBSD (NewsForge)
If you want to judge any entity particularly harshly, judge Sun. Yearly
they hold interoperability events, for NFS and other protocols, and they
include SSH implementation tests as well. Twice we asked them to cover the
travel and accommodation costs for a developer to come to their event, and
they refused. Considering that their SunSSH is directly based on our code,
that is just flat out insulting. Shame on you Sun, shame, shame, shame.
I will say it here -- if an OpenSSH hole is found that applies to SunSSH,
Sun will not be informed. Or maybe that has happened already.
Emphasis mine.
I must say I find this comment disturbing even from Theo de Raadt. The
idea of trying withhold information about security problems does not
belong to free software, especially to such critical free software. I
thought the point with the BSD license was supposed to be that it does not
require corporations to give back to the community.
(
Log in to post comments)