Re: Yet another NTP security bug we fixed before the CVE issued

2016-10-28 Thread Eric S. Raymond
Harlan Stenn : > Interleave is the best way to get the next major step in accurate time > using the NTP Protocol. Yes, it needs work. A reference implementation > is where this work happens. Daniel Franke judges the interleave concept doesn't actually work well enough to be worth its code weight

Re: Yet another NTP security bug we fixed before the CVE issued

2016-10-28 Thread Harlan Stenn
"Eric S. Raymond" writes: > ... Yawn. We disabled interleave a while ago. Interleave is the best way to get the next major step in accurate time using the NTP Protocol. Yes, it needs work. A reference implementation is where this work happens. Yes, we have another release about to happen. Mo

Yet another NTP security bug we fixed before the CVE issued

2016-10-28 Thread Eric S. Raymond
http://forums.theregister.co.uk/forum/1/2016/10/28/researchers_tag_new_brace_of_bugs_in_ntp_but_theyre_fixable/ That'd be another CVE that NTPsec dodges before it's issued. We removed interleaved mode months ago because the code smelled bad and turned out to have an implementation error in the ti