Adam,

Your enumerated rant amounts to little more than waffle if the communities
of people that have listened to your oblique claims about a bug in what is
arguably the most popular Linux variant on the market today can't do
anything about it.

If there's one thing I'm rapidly learning from this encounter, it's that
your approach to the problem puts you on the outer of the open source and
security communities, both of which are willing and able to help locate,
describe and fix the problem.  Further to this, the fact you're further 
not prepared to open a secure communications channel to either the designated
developers/managers of the code (Linus Torvalds, Alan Cox) or to the
industry standard emergency response teams (AusCERT, CERT, CIAC, etc) and
your request the other day for approx A$60,000 if Scott Howards'
"honeypot" server was broken into are plainly absurd.

A perfect example of where full disclosure of problems works to the
benefit of all is in the (anonymous) release of code for a distributed
denial of service tool called mstream.  The source code to the tool was
sent anonymously to David Dittrich (recently known for his binary analyses
of the trin00, tf2nk and stacheldracht software that was found in the wild
on compromised servers), CERT, AusCERT and the Bugtraq mailing list.
Within two days of the release of this code, analyses were publicly
available and network intrusion software vendors had begun issuing
patches to their customers.  Although the source code release of a
potentially damaging tool might be considered dangerous, administrators
and customers have now been forewarned of it's potential and can atleast
go some way to resolving vulnerability to it.  This differs from your
RedHat bug scenario in that everything but the hype is missing.  Sadly for
RedHat users, they were able to detect and understand the mstream tool in
under two days yet nobody has any inkling of what it is you've been
speaking of for the last couple of months.

In this case, it's what people don't know that will hurt them, if only
because I'd much rather see the information about your alleged bug in the
hands of Linus Torvalds/Alan Cox/AusCERT/CERT than yours.  Atleast they've
been known to deal with such things responsibly in the past.

Regardless of the above, I wish you luck in demonstrating your alleged bug
and eagerly await a description of it lest it be fixed quickly for those
customers/users of RedHat Linux.

Grant


References:

AusCERT Secure Communications web page:
http://www.auscert.org.au/Information/Auscert_info/secure_comms.html

CERT "Sending Sensitive Information" web page:
http://www.cert.org/contact_cert/encryptmail.html




-------------------------------------------------------
Grant Bayley                         [EMAIL PROTECTED]
-IT Manager @ Batey Kazoo            (www.kazoo.com.au)
-Admin @ AusMac Archive, Wiretapped.net, 2600 Australia
 www.ausmac.net   www.wiretapped.net   www.2600.org.au
-------------------------------------------------------


--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to