Old IPSEC bug

2010-12-17 Thread Joachim Schipper
I'm sure most of you are already aware, but http://news.ycombinator.com/item?id=2014004 suggests that Jason fixed a potentially-dangerous bug in the IPSEC code in the NETSEC timeframe (src/sys/netinet/ip_esp.c r1.75). Joachim

Re: Old IPSEC bug

2010-12-17 Thread Theo de Raadt
I'm sure most of you are already aware, but http://news.ycombinator.com/item?id=2014004 suggests that Jason fixed a potentially-dangerous bug in the IPSEC code in the NETSEC timeframe (src/sys/netinet/ip_esp.c r1.75). A developer fixed a bug? Oh my lord. Fixing bugs is what developers do.

Re: Old IPSEC bug

2010-12-17 Thread J Sisson
On Fri, Dec 17, 2010 at 10:24 AM, Theo de Raadt dera...@cvs.openbsd.orgwrote: This project -- with it's limited manpower -- is going to remain deeply inconsistant at (a) realizing the impact of a bug fix and (b) making an errata available. That's the beauty of OpenBSD, though...a dev sees a