Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 12 Sep 2012 16:28:17 -0400
From:      John Baldwin <jhb@freebsd.org>
To:        freebsd-security@freebsd.org
Cc:        Arthur Mesh <arthurmesh@gmail.com>, Doug Barton <dougb@freebsd.org>, freebsd-rc@freebsd.org, obrien@freebsd.org, RW <rwmaillists@googlemail.com>, Xin Li <delphij@delphij.net>
Subject:   Re: svn commit: r239569 - head/etc/rc.d
Message-ID:  <201209121628.18088.jhb@freebsd.org>
In-Reply-To: <504F0687.7020309@FreeBSD.org>
References:  <50453686.9090100@FreeBSD.org> <20120911082309.GD72584@dragon.NUXI.org> <504F0687.7020309@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tuesday, September 11, 2012 5:38:15 am Doug Barton wrote:
> >>> Also, both jbh <201209050944.38042.jhb@freebsd.org> and RW
> >>> <20120905021248.5a17ace9@gumby.homeunix.com> feel this likely does
> >>> happen just from reading the code.  Please explain from either
> >>> (1) a code reading, or (2) your own instrumented kernel that dropping
> >>> of input to /dev/random does not occur.
> >>
> >> Once again, you're the one asserting that there is a problem with a
> >> system that has worked well for 12 years, so the burden of proof is on
> >> you. That said, I'm interested in Arthur's evidence.
> > 
> > Are you not a sufficient C programmer that you couldn't hack this up
> > yourself with the amount of time you've spent arguing it? 
> 
> Seriously. Stop being such an ass.
> 
> I've said lots of times now that my FreeBSD time is limited, and THE
> BURDEN OF PROOF IS ON YOU. If you think it's easy, whip it up. If you're
> right, the truth will benefit all of us.

Having watched this thread mostly from the outside, I have to say this much:  
this is a really rediculous argument that works both ways.  Just because we 
don't have a documented vulnerability doesn't mean it doesn't exist either.  
Also, you are clearly wrong about /dev/random dropping input and refuse to
admit that.  To me that taints all your other claims and really weakens your 
arguments.

-- 
John Baldwin



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201209121628.18088.jhb>