[170939] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: [[Infowarrior] - NSA Said to Have Used Heartbleed Bug for Years]

daemon@ATHENA.MIT.EDU (Randy Bush)
Sun Apr 13 10:53:02 2014

Date: Sun, 13 Apr 2014 23:52:32 +0900
From: Randy Bush <randy@psg.com>
To: Michael Thomas <mike@mtcc.com>
In-Reply-To: <534AA308.5080509@mtcc.com>
Cc: North American Network Operators' Group <nanog@nanog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

>> the point of open source is that the community is supposed to be doing
>> this.  we failed.
> Versus all of the closed source bugs that nobody can know of or do 
> anything about?

for those you can blame the vendor.  this one is owned by the community.
it falls on us to try to lower the probability of a next one by actively
auditing source as our civic duty.

randy


home help back first fref pref prev next nref lref last post