, 2006-01-18
A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.
Expand all |
Post comment
How not to respond to a security advisory
2006-01-25
Michael Favinsky (1 replies)
Michael Favinsky (1 replies)

The article isn't defending securelevels as useful or highly secure. It's simply saying they should either be fixed, or removed.
A crude, unqualified "won't fix because it is useless" is a bad position to take here. If it is not worth fixing due to lack of usefulness, it is worth removing the bad code that creates false security.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/380/32988#32988