From owner-freebsd-current Thu Oct 31 10:47:19 1996 Return-Path: owner-current Received: (from root@localhost) by freefall.freebsd.org (8.7.5/8.7.3) id KAA27292 for current-outgoing; Thu, 31 Oct 1996 10:47:19 -0800 (PST) Received: from brasil.moneng.mei.com (brasil.moneng.mei.com [151.186.109.160]) by freefall.freebsd.org (8.7.5/8.7.3) with ESMTP id KAA27281 for ; Thu, 31 Oct 1996 10:47:12 -0800 (PST) Received: (from jgreco@localhost) by brasil.moneng.mei.com (8.7.Beta.1/8.7.Beta.1) id MAA28303; Thu, 31 Oct 1996 12:44:46 -0600 From: Joe Greco Message-Id: <199610311844.MAA28303@brasil.moneng.mei.com> Subject: Re: /var/mail (was: re: Help, permission problems...) To: terry@lambert.org (Terry Lambert) Date: Thu, 31 Oct 1996 12:44:46 -0600 (CST) Cc: scrappy@ki.net, terry@lambert.org, wollman@lcs.mit.edu, jgreco@brasil.moneng.mei.com, current@freebsd.org In-Reply-To: <199610311823.LAA25640@phaeton.artisoft.com> from "Terry Lambert" at Oct 31, 96 11:23:32 am X-Mailer: ELM [version 2.4 PL24] Content-Type: text Sender: owner-current@freebsd.org X-Loop: FreeBSD.org Precedence: bulk > > > He is also the principle author (apparently) of IMAP4, a highly > > > desirable piece of software for anyone with a 1995 or later mail > > > client. > > Agreed...which is why I brought this whole discussion into here... > > > > From what Mark has said, about the only way I can think of for > > getting this *obvious* security bug fixed is to, either: > > [ ... ] > > > IMHO...what having .lock locking capabilities in IMAP4 is > > doing is encouraging system administrators to use NFS mounted mail > > spools, instead of *teaching* system administrators to *not* setup > > their systems that way... > > Or publicize the denial of service attack in the news groups where > IMAP4 is discussed and hope someone uses it. TERRRY! That is perfectly irresponsible :-) As tempting as it may be, and even though I do not believe in security through obscurity as a first line of defense, I do believe that there is some value to security through obscurity. We would be doing less-sophisticated operating systems a great disservice. ... Joe ------------------------------------------------------------------------------- Joe Greco - Systems Administrator jgreco@ns.sol.net Solaria Public Access UNIX - Milwaukee, WI 414/546-7968