Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 12 Oct 2000 03:02:58 +0200 (CEST)
From:      Marius Bendiksen <mbendiks@eunet.no>
To:        Terry Lambert <tlambert@primenet.com>
Cc:        Matt Dillon <dillon@earth.backplane.com>, arch@FreeBSD.ORG
Subject:   Re: cvs commit: src/etc inetd.conf
Message-ID:  <Pine.BSF.4.05.10010120300030.57899-100000@login-1.eunet.no>
In-Reply-To: <200010110527.WAA10938@usr09.primenet.com>

next in thread | previous in thread | raw e-mail | index | archive | help
> > >     isn't poked full of holes when someone turns inetd on without looking 
> > >     at inetd.conf.  I can't imagine why anyone would do that, I guess
> > "If someone points a gun at their foot, and pull the trigger, it is Unix'
> > task to reliably deliver the bullet to it's intended target." - phk, iirc.
> That was actually me; you left off ": in this case, Mr. Foot".

I stand corrected.

> I like the idea of an "anal" package, though...

Indeed. This is a very simple way to provide the security I hear people
call out for, without changing what has worked for us so far. Our task is
to provide our users with tools, not to do their job for them.

There's also an element of false security here. Just like some people
actually get less security than they used to because they buy a firewall
and think that is the end of their problems, we are just building our own
pyre here. Let's not make any claims that we cannot keep, like "secure out
of the box for the past N years" or whatever.

Marius



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-arch" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.05.10010120300030.57899-100000>