Re: Public disclosure of discovered vulnerabilities
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


sci.crypt archive

Re: Public disclosure of discovered vulnerabilities

From: Andrew Reilly <andrew-newspost@areilly.bpc-users.org>
Date: Tue Jun 07 2005 - 07:33:51 CEST

On Mon, 06 Jun 2005 21:38:22 -0700, Paul Rubin wrote:

> "Douglas A. Gwyn" <DAGwyn@null.net> writes:
>> Since that isn't what I was saying at all, apparently you did *not*
>> understand my point. Let me try once more: Since there is ample
>> evidence that "safe" programs can be (routinely) produced *even when
>> the PL is completely "unsafe"*,
>
> Not this again. That evidence is a bunch of programs you claim to
> have written but are unable to show anyone, or even expose to internet
> attack without showing the code. That's pretty unpersuasive.

The entire code-base of OpenBSD?

Qmail?

All sorts of embedded stuff that you probably can't get the source to, but
which observably never breaks anyway?

-- 
Andrew
Received on Thu Sep 29 21:40:55 2005