I find the attitude of such people deplorable.
There must be some way of banning these chaps from this industry....
Here is the link to the original article.
http://australianit.com.au/common/storyPage/0,3811,633573%255E442,00.html
-- Aravind
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Rick Welykochy
> Sent: Wednesday, 3 May 2000 12:33
> To: [EMAIL PROTECTED]
> Subject: [SLUG] Adam Todd - "Put up or Shutup" (fwd)
>
>
> This is getting absurd (on TWO, count 'em TWO other mailing lists),
> but I thought SLUGGERs might like a bit of the entertainment ...
> after all, it is the reputation of our favourite O/S that is
> being tarnsihed here ...
>
>
> ---------- Forwarded message ----------
> Date: Wed, 3 May 2000 12:11:57 +1000 (EST)
> From: Alan Hargreaves <[EMAIL PROTECTED]>
> To: [EMAIL PROTECTED], [EMAIL PROTECTED]
> Cc: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED]
> Subject: Re: [LINK] Re: [Oz-ISP] Adam Todd - "Put up or Shutup"
>
> Adam, at no point did I say that you should have posted the
> description to the
> list. I believe that my actual words were "to have simply replied
> to Scott".
>
> As the demands on your time are high and the the impression that
> I get from what
> little you have said is that it is a relatively simple hack, then
> why not simply
> mail a description of the hack to any of the people that have
> either asked for
> their boxes to be attacked or expressed an interest ing getting
> the problem
> fixed. Perhaps one of them will have more time available to chase
> up properly.
>
> The way that you are handling this is giving the impression that
> you are going
> out of your way to make sure that it does NOT get fixed.
>
> Adam wrote:
> > Gee, 15 minutes on the phone about security and 40 minutes
> about Viper and
> > Albury in the Federal Court. I can see how that priority might
> be confused.
>
> You missed my point Adam. How long would it have taken to
> describe the problem?
> Less than either of those perhaps?
>
> I wrote:
> > >Wouldn't it have been simpler and more productive to have simply
> > >replied to Scott with something like "I don't have the time
> available to
> > >take up your challenge, however, this is what the problem is."
>
> Adam Replied
> > Oh sure, but I got so much email from so many people begging me
> to reasons
> > as to why I've got better thigs to do. How could I resist the
> 6 minutes of
> > relaxation and creative writing to formulate a reply that,
> appears to have
> > entertained a number of people.
>
> Ahh, so your prioritisation places entertaining people on Link
> above fixing a
> serious security bug in a widely used operating system.
>
> > >By refusing any comment on the "bug" other than "I've got a
> secret", you
> > >are not doing your professional reputation a lot of good.
> >
> > I haven't done any such thing. I've been told off on both
> lists before for
> > providng too much or too complex levels of detail. I did my best to
> > provide an overview and open an opportunity for dialouge with anyone
> > seriously interested.
>
> You may not be aware of it, but it is exactly what you are doing.
> What exactly makes you believe that nobody who has asked you for
> details is not
> seriously interested? I recall Rob Hart expressed an interest and
> I didn't see
> anything constructive from you there (admittedly I have no idea
> if you DID take
> him up in private email as would probably have been apropriate).
>
> > If Scott was serious, he'd just publish the IP address, but no, he's
> > playing a game. He is not affording the opportunity for me to attampt a
> > hack on his box with certainly. He wishes to set triggers and
> salarms on a
> > sniffer to therefore do anything he can to stop the data from
> the "knwon ip
> > addresses" in order to allow the process to fail.
>
> What would this gain anyone?
>
> If there is a real problem, then the idea of the extra monitoring
> is to get as
> much information as possible in order to get the bug fixed. This
> is the aim of
> the exercise isn't it?
>
> > Bit like me offering yu a challenge. Alan, I want you to write me a 10
> > page document in Microsoft Word formated document. You can't use any
> > application that exports or saves in the format. You must code the
> > document by hand using the "echo" command under Unix and
> further you can't
> > use a Unix Machine.
> >
> > Pretty dumb huh?
>
> I fail to see any similarity at all.
>
> > How about this. After 12 May I'll take up Scotts challenge under the
> > following condition:
> >
> > 1. Scott pay me in cleared funds an amount of $5000.
> > 2. If I can't break the box I will make a formal and public
> appology on list
> > and in the media for full circulation.
> > 3. If I do break the box, Scott sends me $5000 a month for 12
> months based
> > and issues a public appology for full circulation on list and media.
> >
> > Sounds pretty good to me.
>
> Sounds pretty mercenary to me. Basically what you are saying is
> that you know of
> a major security hole, but you won't tell anyone what it is
> unless there is a
> lot of money it it for you.
>
> I don't think that Scott is the one playing games.
>
> alan.
>
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
>
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text