[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian Investigation Report after Server Compromises



On Tue, 2003-12-02 at 11:31, Greg Folkert wrote:
> Shoulda Been:
> http://lists.debian.org/debian-announce/debian-announce-2003/msg00003.html
> 
> What a wanker I am. No, Peter no comment needed.
> 
> On Tue, 2003-12-02 at 11:08, Greg Folkert wrote:
> >
> http://lists.debian.org/debian-announce/debian-announce-2003/msg00003.htmlDebian

Thanks for the link. It certainly makes for interesting reading. Though
I am somewhat concerned about the following bit from the message:

"Please understand that we cannot give away the used exploit to random
people who we don't know.  So please don't ask us about it."

I'm afraid I'm part of the group that just doesn't understand. This
snippet reeks of security through obscurity for me. If the hole has been
identified and, presumably, fixed, why not tell people about it?

-- 
Alex Malinovich
Support Free Software, delete your Windows partition TODAY!
Encrypted mail preferred. You can get my public key from any of the
pgp.net keyservers. Key ID: A6D24837

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: