Re: Trusting COTS - What's really in the box?

2004-06-10 Thread Sean Donelan
On Mon, 7 Jun 2004, Randy Bush wrote: > building from certifiable open source that has been inspected > by many is the only half-credible scheme of which i am aware. More flaws foul security of open-source repository By Robert Lemos Staff Writer, CNET News.com http://news.com.com/2100-7344-522975

Re: Trusting COTS - What's really in the box?

2004-06-07 Thread Suresh Ramasubramanian
Sean Donelan wrote: How do you know what you get in the box is the same as what was shipped from the factory? Or was it just re-sealed and put back on the shelf with an altered configuration? 1. Buy a linksys box off the shelf from radio shack or wherever [factory sealed] 2. Download the latest

Re: Trusting COTS - What's really in the box?

2004-06-07 Thread Randy Bush
>> Several third party firmwares for the linksys wrt54g wireless AP + >> "router" (which, of course, is owned by brand C) implement sshd using >> dropbear. For example, the ones at sveasoft, and at h.vu.wifi-box.net > > How do you know what you get in the box is the same as what was > shipped fro

Trusting COTS - What's really in the box?

2004-06-07 Thread Sean Donelan
On Tue, 8 Jun 2004, Suresh Ramasubramanian wrote: > Several third party firmwares for the linksys wrt54g wireless AP + > "router" (which, of course, is owned by brand C) implement sshd using > dropbear. For example, the ones at sveasoft, and at h.vu.wifi-box.net How do you know what you get in th