Re: Recent security announcement and csup/cvsup?

2012-11-18 Thread b. f.
On 11/18/12, Claude Buisson wrote: > On 11/18/2012 21:28, b. f. wrote: > > > >> For the base system, and for projects, you should be able to use: >> >> https://svn0.us-west.FreeBSD.org/ >> https://svn0.us-east.FreeBSD.org/ >> >> Unfortunately, AFA

Re: Recent security announcement and csup/cvsup?

2012-11-18 Thread b. f.
On 11/18/12, Gary Palmer wrote: > On Sat, Nov 17, 2012 at 05:07:16PM +0100, M. Schulte wrote: >> Hi, >> >> > Can someone explain why the cvsup/csup infrastructure is considered >> > insecure [...] >> >> Speaking of cvsup security -- correct me if I'm wrong, but as far as I >> know cvsup is general

Re: Malloc -Z

2011-07-27 Thread b. f.
On 7/27/11, Poul-Henning Kamp wrote: > In message , Sean > writes: > >>It's been part of the language standard for over 20 years now, [...] > > Much longer, it's specifically mentioned in the old testament. > You are referring to this, perhaps?: Isaiah 26:14 They are dead, they shall not live; t

Re: Allegations regarding OpenBSD IPSEC

2010-12-15 Thread b. f.
On 12/15/10, Rob Farmer wrote: > On Wed, Dec 15, 2010 at 07:36, Garrett Wollman > wrote: >> <> said: >> >>> If his allegations are correct, they should be easy to verify. He >>> could post a copy of the NDA and a Freedom of Information Act request >>> could be submitted to verify it. If, as clai

Re: Our aging base system krb5 [heimdal]

2010-06-06 Thread b. f.
>I would love for it to go away entirely, and those base-system >components that depend on it to learn how to use either Kerberos >implementation from ports. (I'd also love for the ancient and broken >base version of libcom_err to go away -- there's no knob to turn it >off, and the shared library

Our aging base system heimdal

2010-06-06 Thread b. f.
Is anybody planning to update the base system heimdal, which has been largely untouched since May 2008? In addition to the many other bug-fixes and improvements in the current version 1.3.3 (see, for example: http://www.h5l.org/releases.html ), there are patches for heimdal vulnerabilities 2010-