Gentoo Archives: gentoo-security

From: Peter Simons <simons@××××.to>
To: gentoo-security@l.g.o
Subject: [gentoo-security] All done and settled
Date: Wed, 10 Nov 2004 15:03:10
Message-Id: 87sm7hiw6q.fsf_-_@peti.cryp.to
In Reply to: Re: [gentoo-security] Re: Out of air (was: Let's blow the whistle) by Lucian Pintilie
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Lucian Pintilie writes:
5
6 > You keep talking about 1.5 years and a simple measure you
7 > know for correcting the problem. That doesn't put you in
8 > a good position either [...]
9
10 Yes, you are right. And it's even worse: Not only did I
11 completely fail to realize this is a problem, I even got
12 paid as a _security consultant_ to help setting up secure
13 servers. And I recommended Gentoo. And took money for it.
14 And for all we know, these servers belong to the NSA by now.
15
16 Which means that I have totally fucked up the job my clients
17 trusted me to do and when the details of this problem reach
18 the consciousness of the "general public", there will be
19 questions asked and I will look like an idiot to my clients,
20 not like a hero who "blew the whistle". Because they
21 couldn't care less about technical details, they only care
22 about security.
23
24 Note, however, that I spoke up and raised all hell the
25 _minute_ I learned about this problem. Perhaps those people
26 who are questioning my motivations and my integrity as a
27 human being should consider that before judging what I am
28 trying to do here.
29
30 And while I am at it, I'd also like to point out that those
31 people who have said that this latest revival of the thread
32 was a pointless waste of time that only served to annoy
33 people and didn't help matters at all ... were right, too.
34
35 Because several _hours_ before I started the latest little
36 flame fest here on the list, Kurt had already sent me an
37 e-mail and explained what he thought would be best to do and
38 ask whether I would help. For some weird chance, though, my
39 spam filter decided that this would be a good time to
40 produce the first false-positive in MONTHS and sorted the
41 e-mail into the spam folder, not into my regular mailbox. So
42 I didn't see it and all the while Kurt was waiting for me to
43 reply to him, I was posting and posting on this list
44 shouting and screaming why nothing was being done.
45
46 Rather cool, isn't it?
47
48 And now check this out: No matter how much I feel this was
49 not my fault, no matter how much I believe it was an honest
50 mistake that I couldn't have prevented, it won't change the
51 fact that I fucked up again and uselessly wasted bandwidth,
52 people's time, and did not help matters at all because the
53 answer to all questions was readily waiting in my mailbox
54 already.
55
56 I admit it, I regret it, and I apologize.
57
58 Peter
59
60 -----BEGIN PGP SIGNATURE-----
61 Version: GnuPG v1.2.6 (GNU/Linux)
62
63 iQEVAwUBQZItBUG8KP6ZCJ1yAQL6gwf/Wa4twpkg6rVi4re3Ei+FB8grpPi616Wx
64 zmgQCizI7YLeNVgKBJhvkOjdw4FcOVgt3qcrxK5gquUr6DKBQKUhNv9AM0iz2JPR
65 9fJbKglXy/bwf82uilkNyQ70vuGrIN1ixGYH4x0BqeTBjJvN797RRju4YGcz+2gp
66 0vmyCi9NfdZv/GOUO7viaWJGb6XNcRhZaD5gI4+Tx6wcxNIYds/zG1KTFsQJR1Y4
67 Xij61+RnatFZ2qpapqq6nnbLD9xmVSm1ubpV98307UM+5oY40zmxRGGqCf1bBZVr
68 BnRYo9wLOHzutHJ15j2y6Wf5J32x/oKV81zq6TIeRTG8WHm/TMCTww==
69 =izHL
70 -----END PGP SIGNATURE-----
71
72
73 --
74 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] All done and settled Carsten Lohrke <carlo@g.o>