George Seibel
9 Nov 88

In all due respect, why? It didn't seem to be very effective in closing
the hole in sendmail. Now that everyone is coming out of the woodwork
exclaiming that they've known about this bug for years, I can't help but
wonder why it wasn't fixed. There were a lot of people running around
a couple of weeks ago under the blissful assumption that their computers
were reasonably secure - they had done all the "right" things, vis a vis
file protections, setuid scripts and the like, and all the while, *anyone*
with the appropriate knowledge (and apparently a lot of people had it)
could have done *anything* they wanted to your machine! Perhaps that
was no great surprise to many readers of this newsgroup. Fine. If that's
the way people want it, then let's be up front and print a warning on
each copy of system software that ships: "Congratulations! You just
bought a fine copy of Unix. Don't keep any files you care about on it."
If we have security holes on our machines that are well known, and we
do nothing to patch those holes, we are asking for trouble.

George Seibel

