Fedora Core 2 Test 2 - delayed

Leonard den Ottolander leonard at den.ottolander.nl
Fri Feb 27 15:31:05 UTC 2004


Hi Mike,

> Aside from rejecting SElinux merely due to conspiracy theories
> alone, what would be your suggestion to ensure that this is not
> the case?

I am not rejecting anything, just inquiring. And I am not very in to
conspiracy theories, but the source of this patch is an intelligence
agency, right?

I have no suggestions apart from the code being minutely scrutinized by
people who know how to do that.

> There are quite a few security vulnerabilities found and fixed in 
> OSS source code.  How can you truely be sure that a given 
> vulnerability wasn't planted there intentionally?

I agree that this could be the case with any code, but in this case the
source raises some suspicion. I seem to remember the CIA was involved in
a coup against a democratically elected president only two years ago.
Now who would have expected that in the 21st century? But I am drifting
OT.

> You did upgrade X to the latest version right?  ;o)

I was the one that somewhat prematurely polled you about it in bugzilla.
(Sorry for that, it's just some developers are not as responsive and
fast with releasing security updates as others. And FYI, I am currently
busy downloading the xchat update. It's a pity my mirror (ftp.nluug.nl)
is somewhat slow.)

Leonard.

-- 
mount -t life -o ro /dev/dna /genetic/research






More information about the devel mailing list