develooper Front page | perl.perl5.porters | Postings from February 2000

Re: fixing Sys::Hostname

Tom Christiansen
February 7, 2000 06:23
Re: fixing Sys::Hostname
Message ID:
>>And not a single one of you has paid attention
>>to the tmpfile problem that's triggered a couple dozen bugtraq
>>reports against Perl in the last six months.

>i) I don't think you are in a prime position to tell us what we haven't
>read, thought about and paid attention to.

One infers attention based upon documented response.  The unique
response to the larger issue came from Hank Leininger.  The rest
of you could not be bothered.

>ii) It's been discussed, here, recently. Within the week. Don't you remember?

The only thing that was disussed was that surpassing embarrassment's
particular brokenness.  It is a mistake to focus on the issue in
one program, especially one of such a bastardly heritage and
misdesigned interface.  The broader issue remains, and it is *that*
which is not discussed.  I want to stop treating the symptoms and
start addressing the disease.  No one has risen to that challenge.

If you care about security, please comment on my three proposals
forwarded this morning.  We get beaten up becuase of this stuff.
And it's just going to get worse.  I spent many, many hours last
week wrestling with the whole bugtraq issue in private mail with
many of its member.  Those are what I came up with.  I don't know
if they're the optimal approach, but in the absence of commentary
to the contrary, I have to choice but to assume they are perfect
and acceptable, and that none shall complain when they show up.

--tom Perl Programming lists via nntp and http.
Comments to Ask Bjørn Hansen at | Group listing | About