| From | Subject | Date |
|---|---|---|
| Maxim Bourmistrov | Re: Allegations regarding OpenBSD IPSEC
Theo,
this thread is DEAD. Drop it.
No one believes in "backdoors" planted into OpenBSD.
I se commits - you dig all over the place.
If "backdoor" existed, then it is gone cause of this digging.
Without proof its just a plain BS.
P.S.
I lost my interest for a while ago now.
| Dec 17, 11:34 am 2010 |
| Theo de Raadt | Re: Allegations regarding OpenBSD IPSEC
If that is the case -- that people would dismiss it automatically --
then the community is really stupid. You are almost arguing that that
is the way it should be.
Allegation of not, code should always be checked, and re-checked, and
re-checked.
What I am seeing is that we have a ridiculously upside-down trust
model -- "Trust the developers".
We never asked for people to trust us. We might have "earned some" in
some people's eyes, but if so it has always been false, even before
this. ...
| Dec 17, 11:23 am 2010 |
| Theo de Raadt | Re: Allegations regarding OpenBSD IPSEC
As for promoting his company, someone yesterday showed me this:
http://www.sunbiz.org/scripts/ficidet.exe?action=DETREG&docnum=G09000158184&rd...
Whoa, wait a second here. If you think I gave it credibility, you
need to go back and read my words again. I called it an allegation,
and I stick with that. I was extremely careful with my words, and you
are wrong to interpret them as you do.
| Dec 17, 8:59 am 2010 |
| Pawel Veselov | Re: Allegations regarding OpenBSD IPSEC
On Fri, Dec 17, 2010 at 7:59 AM, Theo de Raadt <deraadt@cvs.openbsd.org>
wrote:
Look, if somebody like me posted something like this here, it would be just
plain dismissed. If Perry posted his email here, he'd just be under fire to
show some or any proof. The reason this was so widely picked up
and generated so much flame and buzz, is because you posted it here.
It's an unfortunate consequence of a right action, really. I'm not even
remotely saying that you intended to give it weight, or that ...
| Dec 17, 11:09 am 2010 |
| Marc Espie | Re: Allegations regarding OpenBSD IPSEC
Theo, it's hopeless. Kids these days. Can't read, can't code.
If you write anything, you can be certain they will take it out of context.
They don't understand what a context is.
Heck, they will use the excuse that they're "not native speakers" to say
they misunderstood.
I mean, why should they make the effort ? it's so easier to take a rumor
out of context, not verify the source, not verify what it says and run
with it.
There's NEVER an excuse for mediocrity. I'm not a native ...
| Dec 17, 10:39 am 2010 |
| Daniel E. Hassler | Re: Allegations regarding OpenBSD IPSEC
I agree with Marc - "it's hopeless" We live in a world where spin is
king. Anything you say can and will be twisted against you.
| Dec 17, 12:21 pm 2010 |
| Top Shop | Garantovano najniže cene!
Top Shop
-10% za Vas i Va
| Dec 17, 4:58 am 2010 |
| Consilier CFI | Vacante si proprietati
Daca aveti probleme cu vizionarea acestui email dati [click aici] pentru
a vizualiza varianta online!
[IMAGE]
[IMAGE]
Newsletter 14.12.2010
[IMAGE]
CaseFaraIntermediari.roUrmariti-ne pe Facebook!Urmariti-ne pe Twitter!Urmariti-ne pe Blogger!
Ultimele anunturi adaugate
Vezi toate anunturile
[IMAGE]
[IMAGE]
Vila 4 camere - Bucurestii Noi
Vila 4 camere - Bucurestii Noi
2.800 EUR/luna
INCHIRIERE
DETALII ;
[IMAGE]
[IMAGE]
[IMAGE]
[IMAGE]
Vila 4 ...
| Dec 17, 2:09 am 2010 |
| Mark Kettenis | Dec 17, 10:20 am 2010 | |
| Marco Peereboom | Re: ld.so fix for empty LD_PRELOAD
I kind of disagree with you mark and I think that the diff makes sense.
| Dec 17, 7:21 am 2010 |
| Mark Kettenis | Re: ld.so fix for empty LD_PRELOAD
I'd say it works just fine without your fix. If you really don't want
| Dec 17, 3:48 am 2010 |
| Theo de Raadt | Re: Allegations regarding OpenBSD IPSEC
Yes, and he's American, so he'd never be brave enough to break any
rules and risk certain death (or worse -- forclosure).
So we know for certain, or we don't.
Yeah, I know -- we live in an incredibly simple world inhabited by
extremely simple people, except when it isn't.
| Dec 16, 9:55 pm 2010 |
| Theo de Raadt | Re: Allegations regarding OpenBSD IPSEC
I think you are totally misreading espie.
It is an allegation in a world where we audit whether there is an
allegation or not.
If I read you right, what you are saying can be simplified to this:
Because this is an allegation, we need not audit. Hey, let's post
instead!
I am sorry, but even if you don't mean it exactly like that, what you
said will be interpreted by many people to mean that. What I see you
say above ridiculous.
You can say keep interpreting things so ...
| Dec 16, 9:47 pm 2010 |
| Rod Whitworth | Re: Allegations regarding OpenBSD IPSEC
Gee, even the google page translation makes it clearer than my rusty
frangais (` mon icole secondaire de trop nombreuses annies il ya).
Thanks for the laughs, Marc.
*** NOTE *** Please DO NOT CC me. I <am> subscribed to the list.
Mail to the sender address that does not originate at the list server is tarpitted. The reply-to: address is provided for those who feel compelled to reply off list. Thankyou.
Rod/
---
This life is not the real thing.
It is not even in Beta.
If it was, then ...
| Dec 16, 5:51 pm 2010 |
| (private) HKS | Re: Allegations regarding OpenBSD IPSEC
On Thu, Dec 16, 2010 at 4:47 AM, Joachim Schipper
OpenBSD is a great product, but y'all are too easily trolled.
His NDA with the FBI *expired* so he 1) discloses information that's
privileged at the very least and a political stick of dynamite at
worst, 2) discloses it in a private forum to an individual known for
his transparency and total lack of tact, 3) doesn't bother contacting
anyone in the press about it, 4) claims to know various other pundits
are "on the FBI payroll," and 5) claims ...
| Dec 16, 8:02 pm 2010 |
| SJP Lists | Re: Allegations regarding OpenBSD IPSEC
That is what I would expect.
From memory, in my part of the World if you did this sort of work for
an intelligence agency, your role and work is kept secret until 40
years *after* your death.
| Dec 16, 9:33 pm 2010 |
| Martin Pelikan | Re: dhclient-script and resolv.conf
Have you considered using something like openresolv in the base
system? I'll be probably reworking my RDNSS implementation in rtsold
and rtadvd because of the new RFC 6106, which is already in "standards
track". Of course it adds another fighter over resolv.conf...
--
Martin Pelikan
| Dec 17, 4:50 am 2010 |
| Kenneth R Westerback | Re: dhclient-script and resolv.conf
This looks like a step forward, and worth trying out. ok krw@.
.... Ken
| Dec 17, 5:48 am 2010 |
| Carson Harding | Re: Allegations regarding OpenBSD IPSEC
The item I find interesting in all this is one I have not seen
commented on:
"the FBI implemented a number of backdoors and
side channel key leaking mechanisms into the OCF,
for the express purpose of monitoring the site to
site VPN encryption system implemented by EOUSA"
Two things come immediately to mind:
1. If I legitimately need access to monitor traffic over
a VPN I either have access to an endpoint, or I have
the keys. Or a warrant.
2. OpenBSD was (is) ...
| Dec 16, 7:27 pm 2010 |
| Kevin Chadwick | Re: Allegations regarding OpenBSD IPSEC
Does anyone know if there was an ultimate outcome to the investigation
of side channels supposedly put into DSA by the NSA?
| Dec 17, 4:11 am 2010 |
| Brandon Mercer | Re: Allegations regarding OpenBSD IPSEC
I about talked myself out of believing that this happened after explaining
this to a cow-orker today. They were quite surprised i'd buy into something
this speculative and far fetched at all. After listening to him generalize
it back to me it seems even sillier.
Brandon
| Dec 16, 5:10 pm 2010 |
| Pawel Veselov | Re: Allegations regarding OpenBSD IPSEC
I'm really sorry to pitch in here, but...
The centerpiece of this thread, besides technical details of how/whether to
prove/disprove the so-called accusations, seems to be an argument on
whether Perry's purely FUD'ing, promoting his company/pages, creating
the buzz, or whether his words should be taken for their face value.
I have to say that Perry here is credited with one thing he actually did not
do -- publish this to the world. There has been talk of alterior motives
here,
but for any ...
| Dec 17, 3:25 am 2010 |
| Miod Vallat | Re: multiple acpihpet devices
The reasoning versus changing acpihpet match function to reject
duplicates and forcing acpihpet0 instead of acpihpet* in the kernel
configuration file should really come down to this:
- if acpihpet attaches to a bus which can be enumerated, then the kernel
configuration file should contain `acpihpet*' and the matching code
should behave correctly.
- if acpihpet attaches to a bus which can not be enumerated, then it
makes sense to move to an `acpihpet0' stanza in the kernel
configuration ...
| Dec 17, 1:48 pm 2010 |
| Jacob Meuser | Re: usb_{bulk,interrupt}_transfer() and PCATCH
after talking with ratchov and deraadt, I am convinced the bug is that
we have a read() interface that can be interrupted but not restarted
reliably. i.e. even if the application deals with EINTR, it's
not reliable because data is lost in the kernel.
so I took a shot at making ugen's read() interface restartable.
diff is below. unfortunately it only works about 90% of the time.
the original diff I sent works 100%. this diff is also a bit
complicated, and still requires complicated ...
| Dec 17, 3:56 pm 2010 |
| previous day | today | next day |
|---|---|---|
| December 16, 2010 | December 17, 2010 | December 18, 2010 |
