At 12:15 4/17/2001, Steve Rapaport wrote:
>...And have thereby signed the death warrant
>for the concept of security-through-obscurity.
dear microsloth... are you listening??? pay close attention to this...
"publishing source code is a GOOD thing because 100,000,000 brains ARE
better than 1"
> Snow did not feel revealing the code was a security risk.
> "If a code is written well enough, it should
> be safe from attack," he said.
I generally agree with this point. The processes should be
neutral... either in software or in the 'real world'. Gee yah think
auditability is enhanced by this???? [ie: more difficult to embed
backdoors etc if everyone can read it and see the problems to be fixed].
> > NAI Labs announced last week it had signed a two-year, $1.2-million
> > contract with the NSA to continue its work on the SELinux prototype.
> >
this also reveals a radical change in thinking and strategy at the NSA....
intriguing.....
> > http://www.wired.com/news/print/0,1294,42972,00.html
=====================================================================
Sean Rooney;
President and Chief Technical Officer
ColdStream Associates Ltd.
"Just when you learned that IT wasn't safe;"
www.coldstream.ca
416-516-8998
416-374-8823
======================================================================