Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 7 Mar 2018 07:31:33 -0800 (PST)
From:      Roger Marquis <marquis@roble.com>
To:        freebsd-security@freebsd.org
Subject:   Re: FreeBSD Security Advisory FreeBSD-SA-18:02.ntp
Message-ID:  <nycvar.OFS.7.76.1803070725100.8841@mx.roble.com>
In-Reply-To: <5131394d-c614-229a-8966-aa3ebaca74b2@nwtime.org>
References:  <20180307071008.BB2B6447F@freefall.freebsd.org> <5131394d-c614-229a-8966-aa3ebaca74b2@nwtime.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Harlan Stenn wrote:
> I still think y'all write great security advisories, and I keep aiming
> to get our "originals" up to your quality.

High quality work to be sure.  It is still unfortunate that time had to
be wasted on this (and other ntpd advisories).  Much time and insecurity
could have been saved by migrating ntpd to ports and openntpd to base.

One too many cases exactly like this are why OpenBSD and HardenedBSD
forked of course, but it is still not at all clear why openntpd and
other tested and proven security changes haven't been pulled in to
FreeBSD.

Roger Marquis



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?nycvar.OFS.7.76.1803070725100.8841>