[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Allegations regarding OpenBSD IPSEC



On Wed, 15 Dec 2010 12:32:47 CST, Paul Schmehl said:
> So for 10 years IPSEC has had a backdoor in it and not one person examining 
> the code has noticed it?  Or even questioned it?

Debian/Ubuntu/etc SSL/SSH key vuln FTW.  That backdoor with a commit
message of 'shut up valgrind' managed to hide for 2 years before anybody
noticed what the effect was....



Attachment: pgph6UH5zhXnu.pgp
Description: PGP signature

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/