Subject: Re: cvs commit: src/lib/libc/db/hash hash_buf.c
To: Poul-Henning Kamp <phk@critter.tfs.com>
From: Theo de Raadt <deraadt@theos.com>
List: tech-userlevel
Date: 10/19/1996 01:06:18
> In message <199610190650.BAA02780@dyson.iquest.net>, "John S. Dyson" writes:
> >> > Additionally, that "fix" was simply the wrong thing to do, and there are
> >> > better ways to deal with the problem.  If the zeroing the buffer in db
> >> > was typical of the ways that others are "fixing" security, well...  Sad...
> > :-(.
> >> 
> >> Ah John, ever eager to continue a flame war aren't you.
> >> 
> >Please refer to the message that I commented on...  I am NOT flaming,
> >simply stating an outsiders view of the unsubstantiated OpenBSD position.
> >BTW, what flame war?  Why are you bringing flamage up?
> >
> 
> Because obviously Theo is Very Proud of his fix :-)

It was not my fix.  However, it is correct.  Perhaps you will spot the
other similar problems before you ship your next release.


You and John are doing great things for inter-camp relations.