Re: Fam mustn't depend on portmap (was Re: new portmap packages, testers wanted)

Scripsit Nathanael Nerode <neroden@twcny.rr.com>

> My apologies for my confusion.  I guess portmap has to be fixed to
> not listen remotely by default then.

Has to? Unless portmap itself contains exploitable security holes,
there's nothing secret about the information it exports, is there?

One might even argue that locking down portmap tight would give users
the false impression that if only you don't tell the bad guys which
port their server is listening on, the bad guys won't be able to
connect to it.

