Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Alex Pennace
On Sat, Jan 26, 2002 at 05:00:52AM +, Lazarus Long wrote: Post your root password and IP address if you think obscurity is irrelevant. (You are twisting a comment about *source* being available for peer review in the crypto community, not about site-specifics being open to all.) Apples

Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Mark Brown
On Sat, Jan 26, 2002 at 05:01:14AM +, Lazarus Long wrote: severity 130876 grave This is definitely a security risk. There is no reason that such information should be exposed to attackers. Just because FreeBSD has That doesn't mean it's a severity grave bug, though. There's no actual

Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Florian Weimer
Lazarus Long [EMAIL PROTECTED] writes: severity 130876 wishlist thanks This is not a bug. This is definitely a security risk. It helps auditing a large farm of Debian machines. For example, there is currently no reliable way to remotely tell if a box running OpenSSH 1.2.3 is

Re: Bug#130876: Very definitely a bug, security

2002-01-25 Thread Lazarus Long
severity 130876 grave thanks On Sat, Jan 26, 2002 at 02:47:20AM +, Jonathan D. Amery wrote: Subject: Bug#130876: Not a bug. severity 130876 wishlist thanks This is not a bug. This is definitely a security risk. There is no reason that such information should be exposed to

Re: Bug#130876: Very definitely a bug, security

2002-01-25 Thread David B Harris
On Sat, 26 Jan 2002 05:01:14 + Lazarus Long [EMAIL PROTECTED] wrote: This is definitely a security risk. There is no reason that such information should be exposed to attackers. Just because FreeBSD has some lame security practices doesn't mean Debian has to emulate them. (If I ran it,