Re: Serious vulnerabilities in GNUnet 0.6.4

"Marcos D. Marado Torres" <[email protected]> Wed, 1 Sep 2004 08:52:07 +0100 (WEST)
Newsgroups gmane.network.gnunet.bugs
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tue, 31 Aug 2004, Christian Grothoff wrote:

> security ("more random").  If you have some insight that changes this
> perception, please share it (and I'll consider changing the protocol once we
> break compatibility big time in the future).

[...]

> c) it is highly likely that this will be fixed once we break compatibility (we
>    have not done on this level since 0.4.x or so and I still do not consider
>    this attack 'strong' or serious enough to justify breaking compatibilty
>    to just fix this problem).

Wouldn't be the right time to brak the compatibility sooner rather then later?
I think that the best thing to do in GNUnet development is to set stuff that
breaks  compatibility between versions as well as security issues as "critical
changes" to do ASAP. While we're getting closer and closer to 1.0, more people
are using GNUnet and inserting stuff, so the later (closer to 1.0) we break
compatibility, less atractive it will be to users...

Mind Booster Noori

- -- 
/* *************************************************************** */
    Marcos Daniel Marado Torres	     AKA	Mind Booster Noori
    http://student.dei.uc.pt/~marado   -	  [email protected]
    () Join the ASCII ribbon campaign against html email, Microsoft
    /\ attachments and Software patents.   They endanger the World.
    Sign a petition against patents:  http://petition.eurolinux.org
/* *************************************************************** */
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
Comment: Made with pgp4pine 1.76

iD8DBQFBNX+smNlq8m+oD34RAlEUAKCG4BM29+/XdEqH21g5ae+njYP/GgCeKPXJ
9DYYgZsd4tsZIs3kR+1e1FE=
=0OwA
-----END PGP SIGNATURE-----