Re: Security through obscurity? (was: ssh + compiled-in SKEYsupport considered harmful?)

2002-04-23 Thread Garance A Drosihn
At 8:44 AM +0930 4/24/02, Greg 'groggy' Lehey wrote: >On Tuesday, 23 April 2002 at 12:06:01 +0200, Jochem Kossen wrote: > >>> *shrug* I was the one who sent in the patch. It was added > >>> some time around 2001/10/26 to the XFree86-4 megaport. When > >>> the metaport was created, the patch was

Re: Security through obscurity? (was: ssh + compiled-in SKEYsupport considered harmful?)

2002-04-23 Thread Garance A Drosihn
At 2:37 PM -0400 4/23/02, Robert Watson wrote: >Here I'll disagree with you: we make a concerted effort to >produce a system that is safe to use. This involves a number >of things, and it doesn't just mean security fixes. I would >argue that we have a moral obligation to do so. I agree that the