Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 27 Sep 1999 12:23:40 -0700 (PDT)
From:      "Rodney W. Grimes" <freebsd@gndrsh.dnsmgr.net>
To:        nate@mt.sri.com (Nate Williams)
Cc:        cjclark@home.com, Cy.Schubert@uumail.gov.bc.ca (Cy Schubert - ITSD Open Systems Group), dillon@apollo.backplane.com (Matthew Dillon), freebsd-security@FreeBSD.ORG
Subject:   Re: dump(8) Insecurity/Misconfiguration
Message-ID:  <199909271923.MAA13029@gndrsh.dnsmgr.net>
In-Reply-To: <199909271903.NAA11566@mt.sri.com> from Nate Williams at "Sep 27, 1999 01:03:08 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
> [ Rod, you *really* need to get out more ]

What, I spent 5 hours yesterday cleaning the side yard at the shop, is
that ``out'' enough for you :-) :-) :-)

> 
> > > "Companies are permitted to use this program as long as it is not used for
> > > revenue-generating purposes. For example, an Internet service provider is
> > > allowed to install this program on their systems and permit clients to use
> > > SSH to connect; however, actively distributing SSH to clients for the
> > > purpose of providing added value requires separate licensing.  Similarly,
> > > a consultant may freely install this software on a client's machine for
> > > his own use, but if he/she sells the client a system that uses SSH as a
> > > component, a separate license is required."
> > > 
> > > I'm no lawyer, but it seems like using SSH for helping with dumps
> > > would fall well within this license since backing up files does not
> > > really generate much revenue for us.
> > 
> > I'm not a lawyer either, but I'll play the advocate here and show
> > you why you are at risk.  First, you used the word ``much'' in the
> > above sentence.  _Any_ is _some_ and is _not_ none, henceforth you
> > voilate ``not used for ...''.  Second, since backups are a critical
> > piece of keeping your business operating
> 
> No, they are not.  Many (most?) businesses are reliably operating
> *today* without a working backup strategy.  Yes, it's stupid, but it
> doesn't effect their ability to do business.  It's just that might not
> work *as* reliably if a disk goes down, but stuff gets done even without
> backups, since backups are rarely needed.

I stated up front I was playing advocate, maybe I should have said devils
advocate, but non the less I think I could make a pretty good case in a
court room that backups are infact a critical piece of keeping a business
running that is dependent upon stored data to run.  Just as insurance in
pretty critical, yet thousands of businesses run around without it.  

I'll bet you dollars to a dog turd that the SSH licensor considers this
a licensable situation.

> 
> > A lot of people will say I have overstated the intent of the licence,
> > I'll simply say that I am applying Blacks Legal dictionary to extract
> > what _I_ see as the letter of the agreement.
> 
> Good thing you are aren't a lawyer.

Probably, I'd be so rich I could be dictating this instead of typing it :-)

> 
> > You may also find that the license fee is quite low for what you want to do.
> 
> NOT!

Then it is even more likely to be outside of the scope of the shareware
license.  If the few is going to be huge for what he wants to do with it
how could you possibly think it would be zero?

-- 
Rod Grimes - KD7CAX - (RWG25)                    rgrimes@gndrsh.dnsmgr.net


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199909271923.MAA13029>