Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Thu, 09 Oct 2014 20:10:19 -0400
From: Chet Ramey <chet.ramey@...e.edu>
To: mancha <mancha1@...o.com>, oss-security@...ts.openwall.com
CC: chet.ramey@...e.edu
Subject: Re: Aftershock

On 10/8/14, 2:37 PM, mancha wrote:

> Maybe LoC is a poor metric but I don't want that to obscure the real
> message: the process's high dynamism post-disclosure. As you correctly
> point out, many recent parser flaws don't rise to the level of security
> concerns primarily because of the prefix/suffix barrier.
> 
> However, it's important to point out that critical piece of hardening
> was a post-disclosure innovation and, more importantly, was triggered by
> post-disclosure findings and interaction.

I absolutely agree, and think it's equally important to point out that
Florian came up with it, not me.  There were other suggestions, some maybe
better, but that was the one we coalesced around.

Chet
-- 
``The lyf so short, the craft so long to lerne.'' - Chaucer
		 ``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, ITS, CWRU    chet@...e.edu    http://cnswww.cns.cwru.edu/~chet/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.