Re: Debian Server Compromise -- A Fire Drill ??

> There is no contradiction.  Many eyes detect most security problems, but 
> not all.  This is certainly better than just a few eyes with access to 
> proprietary code.

There is also the point that *somebody* found this bug.  Just not the
folks we were hoping would. ;-)  Letting real crackers hammer your
system is another way to find bugs, although we hope it's a last resort.

