If I were Red Hat, I would consider legal action against The Australian,
unless they can prove that their statements about the "Red Hat kernel"
having un as-yet undocumented security hole are true.  

Its one thing for Adam Todd to make claims on this list - where we know
him and have formed our own assesment of him.  But to go into print
giving these allegations wider exposure and respectability is a serious
burden on:

1 - Red Hat.

2 - All other distributions.

3 - Open source software in general.

4 - The people who read the article and form false beliefs - so 
    involving them in bad decisions and/or hours spent in 
    argument and research.

As Link is arguably a public forum, due to its searchable web archive,
Adam has a responsibility to all the above to either prove his
allegations or retract them and apologise *ASAP*.

The Australian is certainly a public forum.  The article by Dominique
Jackson does not say that Adam's claims are true, and it does include
contrary views, but I think that giving public prominence and
respectability to grave allegations like this is a costly mistake for
readers and others, and should be either substantiated or prominently
retracted.

The writer should have considered the broader picture - why wasn't this
reported to Red Hat, BugTraq etc?

The final sentence referring to a "backdoor" in Red Hat Linux is gravely
misleading too.  A backdoor, in my understanding, is put there
deliberately and secretly to allow an attacker to breach security.  What
was discovered was an accidental password fault and a but which enabled
an attacker to execute arbitrary commands when entering a password - for
a program which I think is not by default installed.  The article does
not mention that the bug had been reported in the usual constructive way
and that a patch was provided very rapidly.

  http://www.redhat.com/support/errata/RHSA-2000014-16.html

I haven't seen a proper newspaper write-up of how you can crash most
Windows 95/98 machines *completely* (ie. rescusitate with reset button)
by accessing a URL such as file://c:/con/con - including by opening an
HTML email which has an image with such a URL.   Microsoft issued a
patch quick-smart, but I imagine that most machines out there are still
vulnerable.

   http://securax.org/pers/scx-sa-01.txt
   http://www.securityfocus.com/vdb/bottom.html?vid=1043


By the way, the BugTraq list archives, and handy lists of
vulnerabilities can be found at:

   http://www.securityfocus.com/


- Robin
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to