BIND update?

Chris Palmer chris at noncombatant.org
Wed Jul 9 18:38:30 UTC 2008


Wesley Shields writes:

> In the security world there is a balance which must be maintained between
> providing information to consumers so that they may plan accordingly, and
> not providing too much information so that the attackers can write
> exploits; this is the sensitive nature of the information which often
> leads to opaque processes by security teams around the world.

http://en.wikipedia.org/wiki/Kerckhoffs'_principle

Malware authors create exploits based on information they gleaned by reverse
engineering the binary patches released by Microsoft. They are able to get
these exploits into the wild before everyone has even had a chance to apply
the patches, even though the patching is (semi-)automated.

Not only is there no security through obscurity, there isn't even any
obscurity. :)



More information about the freebsd-security mailing list