Re: 2 forwarded messages...DNSEXT discussion of Day and Kaminsky
[email protected] (Paul Jarc)
| Newsgroups | gmane.network.djbdns |
|---|---|
| Organization | What did you have in mind? A short, blunt, human pyramid? |
| Message-ID | <[email protected]> |
Dean Anderson <[email protected]> wrote: > People concerned about security don't take source code from dubious > sources. Right, if those people don't have the time/inclination/capacity to analyze the actual behavior of the patches. If we invest the time and effort to understand the source, we understand the behavior. The patches won't magically take on new behavior behind our backs based on who wrote them. If they have good behavior, we lose nothing by using them, even if they were written by people with bad reputations. Reputation is a good basis for initial guesses, but not for conclusions. You say that Kevin Day is malicious, based on his contact with Dan Kaminsky. You also say that you were involved in the same off-list conversation with them. By your standard, from the information I have, I should conclude that you are malicious. That actually hangs together much more nicely, since you're the one trying to discourage adoption of a change that is known to fix one problem, and that has no new weaknesses that you've been able to explain in a way that anyone else understands. (I don't actually believe you're malicious. But from the information I have, there's more reason to suspect you than Kevin.) > I have a legitimate analysis of the problem; you have seen it; but you > STILL (if above is any indication) can't even repeat it back to me > accurately. As far as I've seen, *no one* can repeat it back to you. *No one* has understood what concrete problems exist in the qmerge patch. It could be that everyone else here is too stupid to measure up to you, but it seems rather more likely that either you simply haven't done a good enough job of explaining the problems, or you're mistaken about their existence. paul