From owner-freebsd-questions@FreeBSD.ORG Fri Dec 17 16:11:22 2010 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 88AFA106564A; Fri, 17 Dec 2010 16:11:22 +0000 (UTC) (envelope-from mike@sentex.net) Received: from smarthost1.sentex.ca (smarthost1-6.sentex.ca [IPv6:2607:f3e0:0:1::12]) by mx1.freebsd.org (Postfix) with ESMTP id 402538FC12; Fri, 17 Dec 2010 16:11:22 +0000 (UTC) Received: from [IPv6:2607:f3e0:0:4:5022:4efd:b73a:4846] ([IPv6:2607:f3e0:0:4:5022:4efd:b73a:4846]) by smarthost1.sentex.ca (8.14.4/8.14.4) with ESMTP id oBHGBI5E031519 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NO); Fri, 17 Dec 2010 11:11:18 -0500 (EST) (envelope-from mike@sentex.net) Message-ID: <4D0B8BA5.5070900@sentex.net> Date: Fri, 17 Dec 2010 11:11:17 -0500 From: Mike Tancsa User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.13) Gecko/20101207 Thunderbird/3.1.7 MIME-Version: 1.0 To: jackoroses@gmail.com References: In-Reply-To: X-Enigmail-Version: 1.1.1 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Scanned-By: MIMEDefang 2.67 on IPv6:2607:f3e0:0:1::12 Cc: security-officer@freebsd.org, FreeBSD Mailing List Subject: Re: FreeBSD IPSec stack contains backdoors? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 17 Dec 2010 16:11:22 -0000 Strange, reads like a totally reasoned response to me to an issue that is somewhere between a practical joke and something critical. I will go with the SECTeam's assessment. They have a proven track record for assessing and dealing with security issues. ---Mike On 12/17/2010 10:36 AM, Mike L wrote: > Reads like an unacceptable response to an issue that seems quite critical. > > > On Fri, Dec 17, 2010 at 4:31 AM, Giorgos Keramidas wrote: > >> The FreeBSD security officer team has already written an official >> response about this. Please have a look at: >> >> >> http://lists.freebsd.org/pipermail/freebsd-security/2010-December/005746.html >> >> Regards, >> Giorgos >> >> On Fri, 17 Dec 2010 14:28:37 +0600, Victor Lyapunov < >> fullblaststorm@gmail.com> wrote: >>> ---------- Forwarded message ---------- >>> From: Victor Lyapunov >>> Date: 2010/12/15 >>> Subject: FreeBSD IPSec stack contains backdoors? >>> To: FreeBSD Mailing List >>> >>> Hi folks, >>> Recently OpenBSD developer Gregory Perry disclosed information about >>> possible backdoors in OpenBSD IPSec stack (see >>> http://permalink.gmane.org/gmane.os.openbsd.tech/22557) In particular, >>> Gregory Perry, who has been working on a OpenBSD -ish implementation >>> of IPSec says a number of backdoors have been introduced into the >>> code. >>> >>> As far as I am aware, FreeBSD contains considerable amount of code >>> ported from OpenBSD. The question is: was the FreeBSD's ipsec code >>> ported from OpenBSD's implementation? If so, what might be the impact >>> of this? >>> >>> Thanks, >>> Victor Lyapunov. >> > _______________________________________________ > freebsd-questions@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-questions > To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org" > >