Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 16 Jul 2000 11:26:16 -0400
From:      Will Andrews <andrews@technologist.com>
To:        Jeroen Ruigrok van der Werven <jruigrok@via-net-works.nl>
Cc:        Hajimu UMEMOTO <ume@FreeBSD.org>, cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   Re: cvs commit: ports/sysutils/gkrellm/files md5
Message-ID:  <20000716112616.A535@argon.gryphonsoft.com>
In-Reply-To: <20000716170202.C57042@lucifer.bart.nl>; from jruigrok@via-net-works.nl on Sun, Jul 16, 2000 at 05:02:02PM %2B0200
References:  <200007161421.HAA35971@freefall.freebsd.org> <20000716170202.C57042@lucifer.bart.nl>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, Jul 16, 2000 at 05:02:02PM +0200, Jeroen Ruigrok van der Werven wrote:
> The security officers would like to know what exactly changed between
> the one version and the other.  For all we know it could've been
> trojaned.

The problem with this is that we don't check new-versioned distfiles for
trojans either.  As we've discussed previously, "all or no security
auditing, there's little point in anything in between".

-- 
Will Andrews <andrewsw@purdue.edu> <will@FreeBSD.org>
GCS/E/S @d- s+:+>+:- a--->+++ C++ UB++++ P+ L- E--- W+++ !N !o ?K w---
?O M+ V-- PS+ PE++ Y+ PGP+>+++ t++ 5 X++ R+ tv+ b++>++++ DI+++ D+ 
G++>+++ e->++++ h! r-->+++ y?


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20000716112616.A535>