Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 09 Apr 2014 08:57:28 -0500
From:      Karl Denninger <karl@denninger.net>
To:        freebsd-security@freebsd.org
Subject:   Re: Proposal
Message-ID:  <534551C8.6030004@denninger.net>
In-Reply-To: <86fvlm7hzj.fsf@nine.des.no>
References:  <CAA3htvtb%2ByZRApEqJ41ue%2B6jB5Y_Une96SYyJRwQXBmQfRZbtQ@mail.gmail.com> <86fvlm7hzj.fsf@nine.des.no>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]

On 4/9/2014 8:25 AM, Dag-Erling Smørgrav wrote:
> Pawel Biernacki <pawel.biernacki@gmail.com> writes:
>> I understand that this is voluntary role and you have another (real
>> life) responsibilities that’s why I'd like to propose an idea of (at
>> least partially) paid position of Security Officer, because we all
>> need quick and efficient response in cases like that.
> Having a paid Security Officer would not have made any difference.
>
> DES
Agreed.

In this particular case FreeBSD's team responded very quickly once the 
threat was known and a resolution path was made available in a very 
expeditious fashion.

The real problem here is the depth of damage and the amount of work to 
rectify it, particularly for those who have certificates issued by 
someone else where **they** may have been compromised.  But this has 
nothing to do with FreeBSD.

-- 
-- Karl
karl@denninger.net



[-- Attachment #2 --]
0	*H
010	+0	*H
O0K030
	*H
010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems LLC CA1/0-	*H
	 customer-service@cudasystems.net0
130824190344Z
180823190344Z0[10	UUS10UFlorida10UKarl Denninger1!0	*H
	karl@denninger.net0"0
	*H
0
bi՞]MNԿawx?`)'ҴcWgR@BlWh+	u}ApdCFJVй~FOL}EW^bچYp3K&ׂ(R
lxڝ.xz?6&nsJ+1v9v/(kqĪp[vjcK%fϻe?iq]z
lyzFO'ppdX//Lw(3JIA*S#՟H[f|CGqJKooy.oEuOw$/섀$삻J9b|AP~8]D1YI<"""Y^T2iQ2b	yH)]	Ƶ0y$_N6XqMC 9՘	XgώjGTP"#nˋ"Bk100	U00	`HB0U0,	`HB
OpenSSL Generated Certificate0U|8˴d[20U#0]Af4U3x&^"408	`HB+)https://cudasystems.net:11443/revoked.crl0
	*H
gBwH]j\x`(&gW32"Uf^.^Iϱ
k!DQAg{(w/)\N'[oRW@CHO>)XrTNɘ!u`xt5(=f\-l3<@C6mnhv##1ŃbH͍_Nq
aʷ?rk$^9TIa!kh,D-ct1
00010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems LLC CA1/0-	*H
	 customer-service@cudasystems.net0	+;0	*H
	1	*H
0	*H
	1
140409135728Z0#	*H
	1JUFR0VO2J0l	*H
	1_0]0	`He*0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems LLC CA1/0-	*H
	 customer-service@cudasystems.net0*H
	1010	UUS10UFlorida10U	Niceville10U
Cuda Systems LLC10UCuda Systems LLC CA1/0-	*H
	 customer-service@cudasystems.net0
	*H
W?@@9ZDQ_{1-1~ :FںP0ϋXiJn=_Ԍk`Mbyѧ>YYMoxx-1t`ϓO 41{_,$"MLn~&{-VUkzh
{D}q_rMonاRw
S<s$(q+~SY!	+30"g7'B-݊_]>Zn1^p-f3,WJyC'{`[~=~	
:-}bKRF	$o%g6CU|@mV^_an"wv)}lyVPCHԌeolRi?3MrǁrzԪ]+,xZq	py8'?"=1J26}2%/,L/N$OS=A4S:lB8ڸ˜i򟂉30$`@QYc?M6o

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?534551C8.6030004>