openbsd-tech mailing list

FromSubjectsort iconDate
Maxim Bourmistrov
Re: Allegations regarding OpenBSD IPSEC
Theo, this thread is DEAD. Drop it. No one believes in "backdoors" planted into OpenBSD. I se commits - you dig all over the place. If "backdoor" existed, then it is gone cause of this digging. Without proof its just a plain BS. P.S. I lost my interest for a while ago now.
Dec 17, 11:34 am 2010
Theo de Raadt
Re: Allegations regarding OpenBSD IPSEC
If that is the case -- that people would dismiss it automatically -- then the community is really stupid. You are almost arguing that that is the way it should be. Allegation of not, code should always be checked, and re-checked, and re-checked. What I am seeing is that we have a ridiculously upside-down trust model -- "Trust the developers". We never asked for people to trust us. We might have "earned some" in some people's eyes, but if so it has always been false, even before this. ...
Dec 17, 11:23 am 2010
Theo de Raadt
Re: Allegations regarding OpenBSD IPSEC
As for promoting his company, someone yesterday showed me this: http://www.sunbiz.org/scripts/ficidet.exe?action=DETREG&docnum=G09000158184&rd... Whoa, wait a second here. If you think I gave it credibility, you need to go back and read my words again. I called it an allegation, and I stick with that. I was extremely careful with my words, and you are wrong to interpret them as you do.
Dec 17, 8:59 am 2010
Pawel Veselov
Re: Allegations regarding OpenBSD IPSEC
On Fri, Dec 17, 2010 at 7:59 AM, Theo de Raadt <deraadt@cvs.openbsd.org> wrote: Look, if somebody like me posted something like this here, it would be just plain dismissed. If Perry posted his email here, he'd just be under fire to show some or any proof. The reason this was so widely picked up and generated so much flame and buzz, is because you posted it here. It's an unfortunate consequence of a right action, really. I'm not even remotely saying that you intended to give it weight, or that ...
Dec 17, 11:09 am 2010
Marc Espie
Re: Allegations regarding OpenBSD IPSEC
Theo, it's hopeless. Kids these days. Can't read, can't code. If you write anything, you can be certain they will take it out of context. They don't understand what a context is. Heck, they will use the excuse that they're "not native speakers" to say they misunderstood. I mean, why should they make the effort ? it's so easier to take a rumor out of context, not verify the source, not verify what it says and run with it. There's NEVER an excuse for mediocrity. I'm not a native ...
Dec 17, 10:39 am 2010
Daniel E. Hassler
Re: Allegations regarding OpenBSD IPSEC
I agree with Marc - "it's hopeless" We live in a world where spin is king. Anything you say can and will be twisted against you.
Dec 17, 12:21 pm 2010
Top Shop
Garantovano najniže cene!
Top Shop -10% za Vas i Va
Dec 17, 4:58 am 2010
Consilier CFI
Vacante si proprietati
Daca aveti probleme cu vizionarea acestui email dati [click aici] pentru a vizualiza varianta online! [IMAGE] [IMAGE] Newsletter 14.12.2010 [IMAGE] CaseFaraIntermediari.roUrmariti-ne pe Facebook!Urmariti-ne pe Twitter!Urmariti-ne pe Blogger! Ultimele anunturi adaugate Vezi toate anunturile [IMAGE] [IMAGE] Vila 4 camere - Bucurestii Noi Vila 4 camere - Bucurestii Noi 2.800 EUR/luna INCHIRIERE DETALII ; [IMAGE] [IMAGE] [IMAGE] [IMAGE] Vila 4 ...
Dec 17, 2:09 am 2010
Mark Kettenis Dec 17, 10:20 am 2010
Marco Peereboom
Re: ld.so fix for empty LD_PRELOAD
I kind of disagree with you mark and I think that the diff makes sense.
Dec 17, 7:21 am 2010
Mark Kettenis
Re: ld.so fix for empty LD_PRELOAD
I'd say it works just fine without your fix. If you really don't want
Dec 17, 3:48 am 2010
Theo de Raadt
Re: Allegations regarding OpenBSD IPSEC
Yes, and he's American, so he'd never be brave enough to break any rules and risk certain death (or worse -- forclosure). So we know for certain, or we don't. Yeah, I know -- we live in an incredibly simple world inhabited by extremely simple people, except when it isn't.
Dec 16, 9:55 pm 2010
Theo de Raadt
Re: Allegations regarding OpenBSD IPSEC
I think you are totally misreading espie. It is an allegation in a world where we audit whether there is an allegation or not. If I read you right, what you are saying can be simplified to this: Because this is an allegation, we need not audit. Hey, let's post instead! I am sorry, but even if you don't mean it exactly like that, what you said will be interpreted by many people to mean that. What I see you say above ridiculous. You can say keep interpreting things so ...
Dec 16, 9:47 pm 2010
Rod Whitworth
Re: Allegations regarding OpenBSD IPSEC
Gee, even the google page translation makes it clearer than my rusty frangais (` mon icole secondaire de trop nombreuses annies il ya). Thanks for the laughs, Marc. *** NOTE *** Please DO NOT CC me. I <am> subscribed to the list. Mail to the sender address that does not originate at the list server is tarpitted. The reply-to: address is provided for those who feel compelled to reply off list. Thankyou. Rod/ --- This life is not the real thing. It is not even in Beta. If it was, then ...
Dec 16, 5:51 pm 2010
(private) HKS
Re: Allegations regarding OpenBSD IPSEC
On Thu, Dec 16, 2010 at 4:47 AM, Joachim Schipper OpenBSD is a great product, but y'all are too easily trolled. His NDA with the FBI *expired* so he 1) discloses information that's privileged at the very least and a political stick of dynamite at worst, 2) discloses it in a private forum to an individual known for his transparency and total lack of tact, 3) doesn't bother contacting anyone in the press about it, 4) claims to know various other pundits are "on the FBI payroll," and 5) claims ...
Dec 16, 8:02 pm 2010
SJP Lists
Re: Allegations regarding OpenBSD IPSEC
That is what I would expect. From memory, in my part of the World if you did this sort of work for an intelligence agency, your role and work is kept secret until 40 years *after* your death.
Dec 16, 9:33 pm 2010
Martin Pelikan
Re: dhclient-script and resolv.conf
Have you considered using something like openresolv in the base system? I'll be probably reworking my RDNSS implementation in rtsold and rtadvd because of the new RFC 6106, which is already in "standards track". Of course it adds another fighter over resolv.conf... -- Martin Pelikan
Dec 17, 4:50 am 2010
Kenneth R Westerback
Re: dhclient-script and resolv.conf
This looks like a step forward, and worth trying out. ok krw@. .... Ken
Dec 17, 5:48 am 2010
Carson Harding
Re: Allegations regarding OpenBSD IPSEC
The item I find interesting in all this is one I have not seen commented on: "the FBI implemented a number of backdoors and side channel key leaking mechanisms into the OCF, for the express purpose of monitoring the site to site VPN encryption system implemented by EOUSA" Two things come immediately to mind: 1. If I legitimately need access to monitor traffic over a VPN I either have access to an endpoint, or I have the keys. Or a warrant. 2. OpenBSD was (is) ...
Dec 16, 7:27 pm 2010
Kevin Chadwick
Re: Allegations regarding OpenBSD IPSEC
Does anyone know if there was an ultimate outcome to the investigation of side channels supposedly put into DSA by the NSA?
Dec 17, 4:11 am 2010
Brandon Mercer
Re: Allegations regarding OpenBSD IPSEC
I about talked myself out of believing that this happened after explaining this to a cow-orker today. They were quite surprised i'd buy into something this speculative and far fetched at all. After listening to him generalize it back to me it seems even sillier. Brandon
Dec 16, 5:10 pm 2010
Pawel Veselov
Re: Allegations regarding OpenBSD IPSEC
I'm really sorry to pitch in here, but... The centerpiece of this thread, besides technical details of how/whether to prove/disprove the so-called accusations, seems to be an argument on whether Perry's purely FUD'ing, promoting his company/pages, creating the buzz, or whether his words should be taken for their face value. I have to say that Perry here is credited with one thing he actually did not do -- publish this to the world. There has been talk of alterior motives here, but for any ...
Dec 17, 3:25 am 2010
Miod Vallat
Re: multiple acpihpet devices
The reasoning versus changing acpihpet match function to reject duplicates and forcing acpihpet0 instead of acpihpet* in the kernel configuration file should really come down to this: - if acpihpet attaches to a bus which can be enumerated, then the kernel configuration file should contain `acpihpet*' and the matching code should behave correctly. - if acpihpet attaches to a bus which can not be enumerated, then it makes sense to move to an `acpihpet0' stanza in the kernel configuration ...
Dec 17, 1:48 pm 2010
Jacob Meuser
Re: usb_{bulk,interrupt}_transfer() and PCATCH
after talking with ratchov and deraadt, I am convinced the bug is that we have a read() interface that can be interrupted but not restarted reliably. i.e. even if the application deals with EINTR, it's not reliable because data is lost in the kernel. so I took a shot at making ugen's read() interface restartable. diff is below. unfortunately it only works about 90% of the time. the original diff I sent works 100%. this diff is also a bit complicated, and still requires complicated ...
Dec 17, 3:56 pm 2010
previous daytodaynext day
December 16, 2010December 17, 2010December 18, 2010