From owner-freebsd-chat@FreeBSD.ORG Mon Aug 18 15:23:44 2003 Return-Path: Delivered-To: freebsd-chat@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E3C2637B401 for ; Mon, 18 Aug 2003 15:23:44 -0700 (PDT) Received: from seattlefenix.net (seattlefenix.net [216.231.34.252]) by mx1.FreeBSD.org (Postfix) with ESMTP id A97D843F75 for ; Mon, 18 Aug 2003 15:23:43 -0700 (PDT) (envelope-from roo@seattlefenix.net) Received: by seattlefenix.net (Postfix, from userid 1001) id F088DB202; Mon, 18 Aug 2003 15:16:03 -0700 (PDT) Date: Mon, 18 Aug 2003 15:16:03 -0700 From: Benjamin Krueger To: Brett Glass Message-ID: <20030818221603.GE10276@surreal.seattlefenix.net> References: <200308140525.XAA02934@lariat.org> <200308140525.XAA02934@lariat.org> <4.3.2.7.2.20030814124234.02a08540@localhost> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4.3.2.7.2.20030814124234.02a08540@localhost> User-Agent: Mutt/1.4i cc: freebsd-crap@FreeBSD.org cc: Kris Kennaway Subject: Re: All "GNU" software potentially Trojaned X-BeenThere: freebsd-chat@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Benjamin Krueger List-Id: Non technical items related to the community List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 18 Aug 2003 22:23:45 -0000 * Brett Glass (brett@lariat.org) [030814 11:38]: > At 01:43 AM 8/14/2003, Kris Kennaway wrote: > > >On Wed, Aug 13, 2003 at 11:25:04PM -0600, Brett Glass wrote: > >> CERT Advisory CA-2003-21 GNU Project FTP Server Compromise > > > >This never would have happened if they had used the BSDL! > > Not true, of course. But on the other hand, the fact that FreeBSD > uses their code means that it may have integrated Trojaned source. > Another reason to avoid using code from a group that's not only > unethical and malicious but also careless about security. > > Kris, as a member of FreeBSD's security team I hope you're checking > to make sure that Trojaned code was not included. (The most effective > way would, of course, be to remove the GNU code from FreeBSD, but while > I'd like to see that done it's probably too much to hope for.) > > --Brett Glass Now Brett, just because you have a bug up your butt about the GPL doesn't mean you get the right to libel the folks who take care of it. -- Benjamin Krueger