[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: rlogind and rexecd go away? [CVS: cvs.openbsd.org: src]
On Thu, May 09, 2002 at 05:00:14AM -0600, Theo de Raadt wrote:
> > Chuck said "rsh is bad", it's his opinion. Obviously, this opinion
> > matches those of many other folks. But why denying people to decide,
> > what is bad and what isn't?
>
> Honestly, the time for such an attitude is over.
>
> Your insecurity is my insecurity. When you make a poor security
> decision, get your connection sniffed, or attacked in some other way,
> then your machine becames an attack machine towards me.
>
> The issue is not really about people who use them in "secure
> environments". It is about people who use them without education.
> And education does not work.
>
> So, increasingly, you will see us supply less of the insecure toolkits
> which suffer from such problems.
>
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."- The Papers of Ben Franklin