Subject: Re: rfc2228 in ftpd
To: None <itojun@iijlab.net>
From: Bill Sommerfeld <sommerfeld@netbsd.org>
List: tech-security
Date: 06/30/2002 20:46:52
> 	i suggested markus to include the reasoning behind the way 3.3 -> 3.4
> 	upgrade path was annouced.  i think it will help a lot of people to
> 	understand why it had to be handled this way.

The reasoning was clear but unreasonable..

The idea that a significant fraction of end users could just
immediately drop everything and upgrade to 3.3 is completely
ridiculous...  particularly since the "privilege separation" features
necessary to defend against the unmentionable bug were *advertised* as
having functional regressions!

					- Bill