public inbox for gentoo-security@lists.gentoo.org
 help / color / mirror / Atom feed
* Re: [gentoo-security] Out of air
@ 2004-11-10  2:05 Denis Roy
  2004-11-10  4:35 ` [gentoo-security] " Chris Frey
  0 siblings, 1 reply; 44+ messages in thread
From: Denis Roy @ 2004-11-10  2:05 UTC (permalink / raw
  To: gentoo-security


>> The reason why I am being confrontational is that if I
>> hadn't been, NOTHING WOULD HAVE HAPPENED!
>
>
> To be honest, I think the whole thread has achieved nothing. 


Nothing except, as we have all seen, annoying the hell out of many
list suscribers including myself.

> not prompted the beginning of a new initiative in signing the tree
because that was already underway. I very much doubt that it'll speed
up the progress made on that initiative, because the main limiting
factor is time. No matter what is said here, it's not going to make
anybody go out and quit their jobs in order to get tree signing
implemented quicker.


Peter: Why don't you join the effort instead or spending your days and
nights trying to talk people into doing it for you? This is open
source. You don't like it? Change it. If you can't? Learn how to. If
you don't want to, well *SWITCH*. Nobody's holding your balls.

Your "advisory" has been heard. Twice over. Either you help or you
wait. If you can't, move along.

Denis Roy 

--
gentoo-security@gentoo.org mailing list


^ permalink raw reply	[flat|nested] 44+ messages in thread
* [gentoo-security] Out of air   (was: Let's blow the whistle)
@ 2004-11-10  1:21 Peter Simons
  2004-11-10  2:25 ` [gentoo-security] Out of air RNuno
  0 siblings, 1 reply; 44+ messages in thread
From: Peter Simons @ 2004-11-10  1:21 UTC (permalink / raw
  To: gentoo-security

A day ago I wrote:

 > At 2004-11-11 00:00:00 CET this article hits a rather
 > popular public full-disclosure mailing list.

The problem with making predictions about by when you'll
have finished something is that you are always wrong. This
is no exception. So please don't be surprised if it won't be
_exactly_ midnight. :-)

I figured I'd better say it now to avoid receiving lots of
e-mails from people telling me that I wouldn't know what
time zone CET is.

Anyway, since there is apparently no more need to discuss
this problem with the "community" -- or at least not on this
mailing list --, I'd like to take the liberty of adding a
few short closing remarks concerning this whole issue.

By now I have stopped counting the number of people who have
called me a public stink, a troublemaker, and whatnot else.
To those who have, I'd like to suggest that you check out a
medieval concept called "hang the messenger". You are
misunderstanding something. Not the people who draw
attention to a vulnerability are causing trouble, the
_vulnerability_ is causing trouble. So instead of attacking
those who are concerned about the lack of authentication in
Gentoo's distribution process, you should, well, fix the
lack of authentication in Gentoo's distribution process. I
wouldn't have thought it was possible, but apparently some
people really need that spelled out for them.

Furthermore, several people have complained that I would be
too confrontational and that I should phrase my messages
more politely if I wanted something to happen about this.
Here is a nice analogy that IMHO puts that into perspective:
You are a car manufacturer and you receive a phone call from
someone who informs you that the breaks in your latest model
have a design flaw that may result in them failing, thus
potentially killing all passengers. And the person who
reports this is really, really rude. Does that mean you
shouldn't fix you breaks?

Oh, and if you think about blowing up on me now because I
implied that the Gentoo developers didn't care about
security: You should really work on your reading
comprehension.

The reason why I am being confrontational is that if I
hadn't been, NOTHING WOULD HAVE HAPPENED!

Oh, and if you think about blowing up on me know because
that would not be true ... then you might want to check the
date of the first time this problem was reported.

Last but not least I cannot help but notice a curious
asymmetry in the way security issues are handled by Gentoo.
It appears that the Gentoo developers are a lot more
forthcoming when it comes to pointing out and fixing
security vulnerabilities in upstream packages (a.k.a.
_other_ people's code) than they are when it comes to
admitting to and fixing problems in their own code.

Oh -- you knew this were coming, right? --, if you think
about blowing up on me know because I just implied that some
people on this mailing list have a MASSIVE ego problem ...
then go ahead. I did.

Having properly antagonized everyone, there remains nothing
left to say. So I'll let some other people speak the last
words. Really, this whole thread has been a diamond mine for
quotes to be readily used on all kinds of occasions. Here
are my personal favorites:

  | I explicitly said that signing should be implemented! I
  | only disagree with the statement that it is a strong
  | security measure or that it's lack is a great danger to
  | Gentoo users.

                    -- Marc Ballarin <Ballarin.Marc@gmx.de>
  http://article.gmane.org/gmane.linux.gentoo.security/1727


  | I wouldn't waste [my time] hypothesizing about a man in
  | the middle attack. While MOTM attacks are theoretically
  | possible on many many protocols, they are *not* a
  | serious threat [...].

                 -- Brian G. Peterson <brian@braverock.com>
  http://article.gmane.org/gmane.linux.gentoo.security/1771

Peter


--
gentoo-security@gentoo.org mailing list


^ permalink raw reply	[flat|nested] 44+ messages in thread

end of thread, other threads:[~2004-11-11 10:57 UTC | newest]

Thread overview: 44+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-11-10  2:05 [gentoo-security] Out of air Denis Roy
2004-11-10  4:35 ` [gentoo-security] " Chris Frey
2004-11-10  4:53   ` Chris Haumesser
2004-11-10  5:08     ` Jason Stubbs
2004-11-10  7:02       ` Chris Haumesser
2004-11-10  7:04         ` Chris Haumesser
2004-11-10  7:22           ` Marius Mauch
2004-11-10 10:03           ` Dominik Schäfer
2004-11-10 13:52     ` [gentoo-security] The solution and hopefully the end Kurt Lieber
2004-11-10 14:00       ` Anthony Metcalf
2004-11-10 14:24       ` [gentoo-security] " Chris Frey
2004-11-10 18:15       ` [gentoo-security] " Gary Nichols
2004-11-10 19:02         ` Joey McCoy
2004-11-10 19:20           ` Michael Gruenberger
2004-11-10 19:57             ` Joey McCoy
2004-11-10 21:22             ` Glen Combe
2004-11-10 21:57               ` William Barnett
2004-11-10 19:26           ` DeadManMoving
2004-11-10 22:17         ` [gentoo-security] " Thomas Kirchner
2004-11-10 22:20           ` Jeff Smelser
2004-11-10 22:26             ` dan
2004-11-10 23:42             ` [gentoo-security] " Thomas Kirchner
2004-11-11  1:16         ` [gentoo-security] " James A. Cox
2004-11-11  1:19       ` Jason Stubbs
2004-11-11  5:45       ` [gentoo-security] " Peter Simons
2004-11-11  8:41         ` [gentoo-security] just can't let it die Chris Haumesser
2004-11-11  9:14           ` Sune Kloppenborg Jeppesen
2004-11-11 10:56       ` [gentoo-security] The solution and hopefully the end Paul de Vrieze
2004-11-10  5:00   ` [gentoo-security] Re: Out of air Jason Stubbs
2004-11-10 12:54     ` Antoine Martin
2004-11-10 12:46       ` Rui Pedro Figueira Covelo
2004-11-10 13:10         ` Antoine Martin
2004-11-10 12:55       ` Klaus Wagner
2004-11-10 13:15         ` Andreas Waschbuesch
2004-11-10 13:26         ` Antoine Martin
2004-11-10 13:31           ` Anthony Metcalf
2004-11-10 14:03             ` Antoine Martin
2004-11-10 13:55               ` Anthony Metcalf
2004-11-10 14:04               ` Calum
  -- strict thread matches above, loose matches on Subject: below --
2004-11-10  1:21 [gentoo-security] Out of air (was: Let's blow the whistle) Peter Simons
2004-11-10  2:25 ` [gentoo-security] Out of air RNuno
2004-11-10  3:07   ` [gentoo-security] " Peter Simons
2004-11-10  3:10     ` Anthony Gorecki
2004-11-10  3:29     ` Marius Mauch
     [not found]     ` <4191882C.3010002@ca.istop.com>
     [not found]       ` <87zn1qtmd2.fsf@peti.cryp.to>
2004-11-10  3:31         ` Den
2004-11-10  3:41           ` Peter Simons

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox