Re: ftp was hacked

From: Tim Haynes (usenet@stirfried.vegetable.org.uk)
Date: 01/03/02


From: Tim Haynes <usenet@stirfried.vegetable.org.uk>
Date: 03 Jan 2002 12:20:44 +0000

Wine Development <wine@sweeney.demon.co.uk> writes:

[snip]
> > Yes. We've encountered it here before over "is qmail secure?" and "just
> > run djbdns instead" and suchlike. It all depends on how much you
> > consider past performance to be an indicator of the future.
>
> I think the crucial matter is - was it patched or rewritten. If patching
> was the 'fix' the the past history is probably a fairly good guide.

Well, yes, that gives you data about turnaround time which a rewrite
wouldn't.

> Only after a couple of years of heavy and widespread use without problems
> can one really say the nasties have probably gone away - look at the
> history of IIS with bugs suddenly being discovered that go back 2 or 3
> releases.

That assumes you believe in a bathtub curve - things either break
immediately or after many years, I think.

> A rewrite (a la Bind8/Bind9) is a different matter, especially if done by
> a different designer+coder combination. Here we have a disjoint, and
> while the new product may turn out to be worse from a security point of
> view the problem history will certainly be different and only time will
> resolve.

One point of view is that this `everything is uncertain' thing is the best
approach to take. It certainly can be if the alternative is something where
patches take ages to turn around for a severe bug.

> I have never subscribed to the 'latest has got to be best' theory, things
> are never that simple, MS (in their usual style in such matters) have
> amply demonstrated that as well.

Latest is less likely to have exploits out there (would you really stick
with installing patches to bind8 when bind9 is available, and has been for
at least a year, in varying degrees of uptodateness, with no reported
vulnerabilities, that I've seen?), and `best' on feature / functionality
grounds. At least, normally so.
I guess you just have to weigh-up each situation as it appears... :)

~Tim

-- 
It's all over the front page                |piglet@stirfried.vegetable.org.uk
You give me road rage                       |http://spodzone.org.uk/
Racing through the best days                |



Relevant Pages

  • Re: OT: Giving up smoking
    ... Rope secured a place in history by writing: ... > tried all sorts in the past, and nothing has worked so far. ... Patches, lozenges, gum and turkey didn't, on several occasions. ...
    (uk.rec.motorcycles)
  • gitweb: kernel versions in the history (feature request, probably)
    ... I see gitweb is much more usable than a few months ago, ... there is one thing a bit problematic: in the history of patches I'm ... this one question, so I'd really feel greteful for forwarding, if you ...
    (Linux-Kernel)
  • Re: [RFC] Linux Kernel Subversion Howto
    ... BK history is not part of "linux kernel", and those who use BK know why they're ... "history" and you had to develop against -pre patches. ... Besides, Larry is exporting most of that story in CVS, so those who accuse ... the "kernel history" using a propietary tool. ...
    (Linux-Kernel)
  • Re: itrc - H.P. I.T. Resource Center.
    ... > is history and HISTORY. ... The HP customer base doesn't use as old-crufty ... > to have a contract for the patches. ... contract, ...
    (comp.os.vms)