Date: Tue, 30 Sep 2014 08:27:24 -0700 From: Ed Prevost <me@...ardprevost.info> To: oss-security@...ts.openwall.com Subject: Re: Healing the bash fork On 9/30/2014 6:41 AM, Kobrin, Eric wrote: >> "innocuous looking setuid program" made my day ;) >> We should take care not to blame all and everything to bash. > I don't find that blame is a useful tool for fixing security problems. What's more interesting to me is: what system components are in a position to help. If a change in bash can make a bunch of "innocuous looking setuid programs" not be vectors for the import of malicious functions, let's do it. > +1 and I swear I'm not some groupie fan-boy paid by Eric.
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.