Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 19 Oct 1996 01:06:18 -0600
From:      Theo de Raadt <deraadt@theos.com>
To:        Poul-Henning Kamp <phk@critter.tfs.com>
Cc:        dyson@freebsd.org, deraadt@theos.com (Theo de Raadt), downsj@teeny.org, ache@nagual.ru, dg@root.com, gritton@byu.edu, freebsd-hackers@freebsd.org, tech-userlevel@netbsd.org, misc@openbsd.org
Subject:   Re: cvs commit: src/lib/libc/db/hash hash_buf.c 
Message-ID:  <199610190707.BAA29373@zeus.theos.com>
In-Reply-To: Your message of "Sat, 19 Oct 1996 09:04:01 %2B0200." <9517.845708641@critter.tfs.com> 

next in thread | previous in thread | raw e-mail | index | archive | help
> In message <199610190650.BAA02780@dyson.iquest.net>, "John S. Dyson" writes:
> >> > Additionally, that "fix" was simply the wrong thing to do, and there are
> >> > better ways to deal with the problem.  If the zeroing the buffer in db
> >> > was typical of the ways that others are "fixing" security, well...  Sad...
> > :-(.
> >> 
> >> Ah John, ever eager to continue a flame war aren't you.
> >> 
> >Please refer to the message that I commented on...  I am NOT flaming,
> >simply stating an outsiders view of the unsubstantiated OpenBSD position.
> >BTW, what flame war?  Why are you bringing flamage up?
> >
> 
> Because obviously Theo is Very Proud of his fix :-)

It was not my fix.  However, it is correct.  Perhaps you will spot the
other similar problems before you ship your next release.


You and John are doing great things for inter-camp relations.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199610190707.BAA29373>