From owner-freebsd-security@freebsd.org Wed Dec 13 09:02:38 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 740E9E96D90 for ; Wed, 13 Dec 2017 09:02:38 +0000 (UTC) (envelope-from michelle@sorbs.net) Received: from hades.sorbs.net (hades.sorbs.net [72.12.213.40]) by mx1.freebsd.org (Postfix) with ESMTP id 4F07268B2F for ; Wed, 13 Dec 2017 09:02:37 +0000 (UTC) (envelope-from michelle@sorbs.net) MIME-version: 1.0 Content-transfer-encoding: 8BIT Content-type: text/plain; charset=UTF-8; format=flowed Received: from typhoon.sorbs.net (203-206-128-220.perm.iinet.net.au [203.206.128.220]) by hades.sorbs.net (Oracle Communications Messaging Server 7.0.5.29.0 64bit (built Jul 9 2013)) with ESMTPSA id <0P0W00E506UOR000@hades.sorbs.net> for freebsd-security@freebsd.org; Wed, 13 Dec 2017 01:11:15 -0800 (PST) Subject: Re: http subversion URLs should be discontinued in favor of https URLs To: =?UTF-8?Q?Dag-Erling_Sm=c3=b8rgrav?= Cc: Yuri , Igor Mozolevsky , freebsd security References: <97f76231-dace-10c4-cab2-08e5e0d792b5@rawbw.com> <20171205220849.GH9701@gmail.com> <20171205231845.5028d01d@gumby.homeunix.com> <20171210173222.GF5901@funkthat.com> <5c810101-9092-7665-d623-275c15d4612b@rawbw.com> <19bd6d57-4fa6-24d4-6262-37e1487d7ed6@rawbw.com> <913910fb-723b-e450-8f02-4c26b3c15287@rawbw.com> <898df78d-c0b1-9e9f-0630-2665c3939960@rawbw.com> <5A2DB9F8.1040301@sorbs.net> <86h8swgnwk.fsf@desk.des.no> <5A3029AC.8040203@sorbs.net> <86zi6nf5s1.fsf@desk.des.no> From: Michelle Sullivan Message-id: <5A30EC23.2000504@sorbs.net> Date: Wed, 13 Dec 2017 20:00:19 +1100 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:43.0) Gecko/20100101 Firefox/43.0 SeaMonkey/2.40 In-reply-to: <86zi6nf5s1.fsf@desk.des.no> X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.25 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 13 Dec 2017 09:02:38 -0000 Dag-Erling Smørgrav wrote: > Michelle Sullivan writes: >> Dag-Erling Smørgrav writes: >>> Banks and financial institutions have whole teams working 24/7 [...] >> No. > I was describing a fact, not opining or speculating. So was I. > I know these > people, I talk to them regularly and meet with them at industry events. I literally cannot tell you what I do for/with them, it would be a breach of contract but if you look closely at some of the larger (non-European) banks, you might spot a clue or three. > Sorry to hear you're not part of the club — that doesn't mean the club > doesn't exist. Absolutely true that. I'm not going to say any more on this subject because it is so tempting for me to say something which could put me in a position that could call into question my employment. Suffice it to say you might be right for Europe, but you should not dismiss my words about parts of the industry that you don't know about. Regards, Michelle