Theo de Raadt on OpenSSH security flaws
Posted Apr 1, 2006 2:49 UTC (Sat) by
Shanep (guest, #36879)
In reply to:
Theo de Raadt on OpenSSH security flaws by man_ls
Parent article:
Interview: Theo de Raadt of OpenBSD (NewsForge)
In the interest of responsible disclosure, developers (open or closed) should be notified as
soon as you learn about a vulnerability, and the general public some time later. This is what de
Raadt does not promise to do.
How much money does Sun have and how many staff members do they have? They give
NOTHING back, yet expect something in return for NOTHING? They have the staff and resources
to monitor the advisories themselves. They should not need and do not deserve a personal
touch.
And it is really a disturbing attitude, given that OpenBSD people are always advocating
complete freedom for their source code, even if it means that competitors may take it and
release a closed version. Or I should say especially when competitors take it and release a closed
version, since these people claim the superiority of their license for this same reason. We must
conclude that they do not think closed versions are a bad thing.
It is about freedom of OpenBSD's OWN source code. That freedom is absolute when you allow
people to take it for themselves and close their own copy and development off to the rest of the
World. OpenBSD's version remains as free as possible.
(
Log in to post comments)