Full Disclosure mailing list archives

Re: Allegations regarding OpenBSD IPSEC


From: Valdis.Kletnieks () vt edu
Date: Wed, 15 Dec 2010 14:39:06 -0500

On Wed, 15 Dec 2010 12:32:47 CST, Paul Schmehl said:
So for 10 years IPSEC has had a backdoor in it and not one person examining 
the code has noticed it?  Or even questioned it?

Debian/Ubuntu/etc SSL/SSH key vuln FTW.  That backdoor with a commit
message of 'shut up valgrind' managed to hide for 2 years before anybody
noticed what the effect was....



Attachment: _bin
Description:

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: