Re: Debian libssl security (Cause???)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Ted Unangst <ted.unangst@...>
Cc: <ross.cameron@...>, <misc@...>
Date: Saturday, May 17, 2008 - 2:36 am

On Fri, May 16, 2008 at 04:02:48PM -0400, Ted Unangst wrote:

> On 5/16/08, Ross Cameron wrote:

Yeah, using tools such as valgrind can help a lot, but the danger side
is that it will cause actions to be taken by people who do not
understand the code, just to silence valgrind. Since valgrind flags
the location of the use of uninialized mem, and--of course--not the
root cause, developers can easily be mislead and apply the wrong fix.
I think we have a clear demonstration of the danger of using a tool
without proper understanding of the code here. In addition, the vague
posts from both sides on openssl-dev mailing lists did not help too.

-Otto

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Debian libssl security (Cause???), Ross Cameron, (Fri May 16, 7:31 am)
Re: Debian libssl security (Cause???), Otto Moerbeek, (Fri May 16, 7:41 am)
Re: Debian libssl security (Cause???), Ross Cameron, (Fri May 16, 8:30 am)
Re: Debian libssl security (Cause???), Ted Unangst, (Fri May 16, 4:02 pm)
Re: Debian libssl security (Cause???), Otto Moerbeek, (Sat May 17, 2:36 am)
Re: Debian libssl security (Cause???), Tim Post, (Sat May 17, 3:12 am)
Re: Debian libssl security (Cause???), Travers Buda, (Fri May 16, 2:33 pm)
Re: Debian libssl security (Cause???), mcb, inc., (Fri May 16, 3:06 pm)