Subject: Re: Re: lib/30923
To: Zafer Aydogan <firstname.lastname@example.org>
From: Martin Husemann <email@example.com>
Date: 08/26/2005 00:15:44
On Thu, Aug 25, 2005 at 11:00:54AM +0200, Zafer Aydogan wrote:
> Rui, you don't seem to get it. A Message is printed by syslog on the
> console. The Message that should be removed is on the remote end.
> That is a security issue!
Apparently it is not clear to everyone that the traditional behaviour
suddenly is wrong from a security POV (or noone uses telnetd any
more nor runs insecure ttys).
A PR is not the right place to discuss this - maybe bring this up on
tech-security and if consensus is reached, someone might apply the
rumored patch (the PR has no patch, as of a few minutes ago).