Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 16 Aug 2006 11:58:51 +0200
From:      =?ISO-8859-1?Q?=22Jos=E9_M=2E_Fandi=F1o=22?= <freebsd4@fadesa.es>
To:        freebsd-security@freebsd.org
Subject:   Re: atheros chips dangerous?
Message-ID:  <44E2EC5B.3010007@fadesa.es>
In-Reply-To: <20060811123921.K43265@volatile.chemikals.org>
References:  <38802.1155288265@critter.freebsd.dk> <20060811123921.K43265@volatile.chemikals.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Wesley Morgan wrote:
>> Other vendors have been totally impossible to work with.
> 
> 
> I agree, the Atheros driver is fantastic. The driver may be "binary" in 
> some ways, but I think we got the best of both worlds. The vendor is 
> providing every scrap of information necessary without having to give 
> away trade secrets, and FreeBSD got a driver authored by a developer who 
> is probably one of the most qualified people in the world to work on it. 
> I know I go out of my way to purchase and recommend Atheros-based 
> wireless devices because of this.

because of this, I'm buying their hardware.

> Anyone who simply makes the blanket assumption that because something is 
> "FOSS" that it gets more peer review need only to look at some of the 
> oldest open source projects around, such as sendmail or XFree/Xorg, to 
> realize that security problems can persist for years without being 
> discovered.

I know that by the mere fact of making it free it isn't automatically
more secure, it needs reviews from people interest in it. But by
reducing the potential number of reviewers with some type of restrictive
contract doesn't help either.

Anyway, as it was commented in this case the solution was reasonable
because the NDA in use is for the 802.11 PHY layer to comply with the
regulatory laws, see:
http://madwifi.org/wiki/HAL#WhyistheHALclosedsource








Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?44E2EC5B.3010007>