, 2006-01-18
A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.
Expand all |
Post comment
How not to respond to a security advisory
2006-01-19
Miles (3 replies)
Miles (3 replies)
How not to respond to a security advisory
2006-01-25
Michael Favinsky (1 replies)
Michael Favinsky (1 replies)

So by doing this the attacker can do more? If he is root to start with then you are kind of screwed anyway. He could have changed non-immutable files regardless of this so called "vulnerability" and at the same time he is still not be able to change any immutable files.
So where is the risk here?
Theo might seem coarse, but he has a proven track record and I think people should wait to hear his rationale before judging him. I have seen lots of non-issues get brought up against OpenBSD and it must get pretty tiring to hear people complain about them.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/380/32984#32984