Theo de Raadt on OpenSSH security flaws
Posted Apr 1, 2006 12:11 UTC (Sat) by
Shanep (guest, #36879)
In reply to:
Theo de Raadt on OpenSSH security flaws by man_ls
Parent article:
Interview: Theo de Raadt of OpenBSD (NewsForge)
De Raadt and others go out of their way to let companies make closed versions. So when it
happens they should not go mad;
Theo is mad that an expectation from Sun and IBM that the OpenSSH project is responsible for
fixing software which Sun and IBM are providing their paying customers. IBM has refused to fix
problems for their customers because they say it is the responsibility of the OpenSSH project.
Well it is NOT OpenSSH's responsibility. IBM wants the benefits of the BSD licence without the
responsibilities that go with it. I would be mad too.
they should instead understand that SunSSH users are also their users and not put them at
risk. It is not ethical (and it looks unprofessional too).
The stance of the OpenBSD project is that they write code for themselves and allow other people
to use that code. I agree that ethically they should provide fixes for users of their own code.
However I don't agree that they should have a responsibility to Sun as Sun being OpenBSD's user.
Because Sun was a user of OpenSSH for the instant that they took it, but then gave that up at the
point where they started making their own changes. Just like people who compile custom
OpenBSD kernels, putting things in, taking stuff out and making mods and then expecting the
OpenBSD project to be able to help them. Sun has chosen to branch OpenSSH into their
own codebase. Now they, Sun, are responsible from not only an ethical standpoint to their (Sun's)
customers, but possibly also from a legal standpoint.
Theo should not have to watch SunSSH development to see what is vulnerable and what is not, as
time goes on and the codebases continue to make distance from each other. Sun is a big
company and like any big company releasing software, they need to deal with the security too.
They take the benefit from the BSD licence, they need to deal with it.
(
Log in to post comments)