nanog mailing list archives

Re: [[Infowarrior] - NSA Said to Have Used Heartbleed Bug for Years]


From: Randy Bush <randy () psg com>
Date: Sun, 13 Apr 2014 23:52:32 +0900

the point of open source is that the community is supposed to be doing
this.  we failed.
Versus all of the closed source bugs that nobody can know of or do 
anything about?

for those you can blame the vendor.  this one is owned by the community.
it falls on us to try to lower the probability of a next one by actively
auditing source as our civic duty.

randy


Current thread: