|
From: Jose N. <jo...@mo...> - 2002-11-12 16:55:44
|
On Tue, 12 Nov 2002, Lurene Angela Grenier wrote: > Hells yeah - that was the suggestion I had last night - then you can > just do thurough checks on the input to the functions that are elevated, > and take the input through lowered functions. lemme properly credit the idea to lurene :) > If the crypto is as bad as you say it is it's probably not a bad idea. so the issue there isn't that they're not using openssl, its that they're just mucking it a bit funnily. i dont trust their seeding, i dont trust their key management in memory after the whole memset 0 thing this past week ... > The BIND4 feature set seems a good first goal, since we can maybe get it > in to current at that point to replace the old bind... sounds good to me. the ipv6 thing is about data and record design. no sense scrapping stuff for ipv6 unless you recognize that from the start. ___________________________ jose nazario, ph.d. jo...@mo... http://www.monkey.org/~jose/ |