Previously Tollef Fog Heen wrote:
> You are assuming that talkd have buffer overflows, but you have no
> proof of it.  And talk is rwxr-xr-x, so what would you win by an
> overflow on a local host?  And I doubt that there are many bugs in a
> daemon which is less than 10k big.

Security works the other way around: assumed vulnerable until proven
otherwise. And for any non-trivial program proof is impossible, so
the best we can do is limit the risks.


