[Fwd: Re: FW:FreeBSD hiding security stuff]

From: Colin Percival (colin.percival_at_wadham.ox.ac.uk)
Date: 03/04/05

  • Next message: Devon H. O'Dell: "Re: FreeBSD hiding security stuff"
    Date: Fri, 04 Mar 2005 05:40:33 -0800
    To: freebsd-security@freebsd.org
    
    

    Well, I *tried* to CC: freebsd-security... I'm forwarding this to
    get around the "posting from wrong address" filter.

    -------- Original Message --------
    Subject: Re: FW:FreeBSD hiding security stuff
    Date: Fri, 04 Mar 2005 04:42:48 -0800
    From: Colin Percival <cperciva@freebsd.org>
    To: Jonathan Weiss <tomonage2@gmx.de>
    CC: freebsd-security@freebsd.org, FreeBSD-Hackers <hackers@freebsd.org>
    References: <BE4E0FDD.1A486%tomonage2@gmx.de>

    [I'm adding a CC: to freebsd-security, since I'm sure this thread will
    get reposted there if I don't. For those not subscribed to -hackers:
    Jonathan forwarded the an email Theo wrote to openbsd-misc:
    http://marc.theaimsgroup.com/?l=openbsd-misc&m=110993373705509&w=2 ]

    Jonathan Weiss wrote:
    > Whats the intention behind the FreeBSD developers policy?

    Quoting from secteam's TODO list for advisories:

    1. Check if security officers need to be contacted at OpenBSD, NetBSD,
    OS X, or DragonFlyBSD.

    Yes, that's item #1 on our list. :-)

    In this case, I wasn't sure if OpenBSD was affected, so I emailed Theo
    asking for certain details which would allow me to make this determination.

    Theo wrote:
    > A few FreeBSD developers apparently have found some security issue
    > of some sort affecting i386 operating systems in some cases.

    s/A few FreeBSD developers/One FreeBSD developer/

    I discovered this issue in December; until a few days ago I was working
    on it to determine whether it could be exploited.

    > They have refused to give us real details.

    Theo, in one of several replies, indicated that I should provide the
    details to Ted Unangst (tedu@). I contacted Ted and provided him with
    the details; he agreed with me about how and when it should be handled
    by OpenBSD.

    > A promise is now being made.
    >
    > If a bug is found in OpenSSH, which we believe to have security
    > consequences, we wil inform FreeBSD last.
    >
    > Fair is fair.
    >
    > I really wish it was not this way, but after a week of trying to get the
    > policy to be fixed, we are changing our policy as well.
    >
    > Without immediate action from them to repair their polcy, and a public
    > apology for this, that policy will stand.

    The policy of the FreeBSD security team is to notify other vendors and work
    with them to co-ordinate a disclosure schedule. It is also the policy of
    the FreeBSD security team to avoid disclosing security issues to anyone who
    does not need to know about them (i.e., anyone other than other affected
    vendors, admins@, and in some cases re@).

    I will make no apology for either of these, and I doubt anyone else (either
    from the security team, or the security officer himself) will do so either.

    Colin Percival
    _______________________________________________
    freebsd-hackers@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
    To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@freebsd.org"

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Devon H. O'Dell: "Re: FreeBSD hiding security stuff"

    Relevant Pages

    • RE: PAWS security vulnerability
      ... FreeBSD security list" isn't grammatically correct. ... "I told you to post the patch and info to the appropriate FreeBSD security ... "...This point and others are often discussed on the mailing lists, ...
      (freebsd-questions)
    • Re: Fwd: FreeBSD hiding security stuff
      ... >>A few FreeBSD developers apparently have found some security issue ... we wil inform FreeBSD last. ... >>policy to be fixed, we are changing our policy as well. ... Matt replied stating that the aforementioned `advisory' wasn't ...
      (FreeBSD-Security)
    • Re: Why not?
      ... >> having totally separate kernel development for different issues. ... A few FreeBSD developers apparently have found some security issue ... policy to be fixed, we are changing our policy as well. ...
      (freebsd-questions)
    • Changes to FreeBSD security support policy
      ... for tracking security fixes to FreeBSD 4.3-RELEASE: ... This eliminates support for the class of vulnerabilities exploitable ...
      (FreeBSD-Security)
    • RE: FreeBSD Security Survey
      ... Your also ignoring the fact that many security holes are a lot ... queries to this server to the NAS only. ... server with a new version of FreeBSD. ... Your survey responses lack any responses that indicate that leaving ...
      (freebsd-questions)