<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Debian needs some serious commit review</title>
	<atom:link href="http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/feed/" rel="self" type="application/rss+xml" />
	<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/</link>
	<description>Embedded security, crypto, software protection</description>
	<lastBuildDate>Mon, 08 Mar 2010 21:19:29 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Nate Lawson</title>
		<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/#comment-4845</link>
		<dc:creator>Nate Lawson</dc:creator>
		<pubDate>Thu, 04 Dec 2008 20:59:03 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.wordpress.com/?p=137#comment-4845</guid>
		<description>Yuhong, it was a private comment to me that I thought was hilarious.</description>
		<content:encoded><![CDATA[<p>Yuhong, it was a private comment to me that I thought was hilarious.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yuhong Bao</title>
		<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/#comment-4842</link>
		<dc:creator>Yuhong Bao</dc:creator>
		<pubDate>Fri, 21 Nov 2008 04:55:21 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.wordpress.com/?p=137#comment-4842</guid>
		<description>BTW, where did the Thomas Ptacek quote come from? Because I can&#039;t find it using Google.</description>
		<content:encoded><![CDATA[<p>BTW, where did the Thomas Ptacek quote come from? Because I can&#8217;t find it using Google.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nate Lawson</title>
		<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/#comment-4702</link>
		<dc:creator>Nate Lawson</dc:creator>
		<pubDate>Mon, 21 Jul 2008 18:47:24 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.wordpress.com/?p=137#comment-4702</guid>
		<description>I was surprised to see this post get so many comments months after it was published.  Looks like Linux Haters brought in the hordes.  I had to delete a few comments that were racist.  Please try to add value with what you write here, don&#039;t just insult others.

With respect to the defense that &quot;disabling seeding is documented behavior&quot;, I think this is a terrible design.  The only valid reason for this is some kind of test mode that should never be used on a live system.  Thus, my recommendation was that enabling this test mode should result in a giant #warning at compile time and printf(&quot;WARNING...&quot;) at runtime.</description>
		<content:encoded><![CDATA[<p>I was surprised to see this post get so many comments months after it was published.  Looks like Linux Haters brought in the hordes.  I had to delete a few comments that were racist.  Please try to add value with what you write here, don&#8217;t just insult others.</p>
<p>With respect to the defense that &#8220;disabling seeding is documented behavior&#8221;, I think this is a terrible design.  The only valid reason for this is some kind of test mode that should never be used on a live system.  Thus, my recommendation was that enabling this test mode should result in a giant #warning at compile time and printf(&#8220;WARNING&#8230;&#8221;) at runtime.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: grfgguvf</title>
		<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/#comment-4686</link>
		<dc:creator>grfgguvf</dc:creator>
		<pubDate>Sat, 12 Jul 2008 23:09:15 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.wordpress.com/?p=137#comment-4686</guid>
		<description>This is nothing new.
I Switched away from Debian years ago because of the crappy patches their &quot;developers&quot; were allowed to apply to packages.

Actually Ubuntu has helped the situation a lot as they pay competent coders to clean up the Debian tree, at least the important packages are mostly fine now.

@sheesh
As for Vista: it still stores passwords as an unsalted hash. Which yes, makes it possible to reverse them in minutes. Look into ophcrack. This has little to do with cryptographic key quality though.</description>
		<content:encoded><![CDATA[<p>This is nothing new.<br />
I Switched away from Debian years ago because of the crappy patches their &#8220;developers&#8221; were allowed to apply to packages.</p>
<p>Actually Ubuntu has helped the situation a lot as they pay competent coders to clean up the Debian tree, at least the important packages are mostly fine now.</p>
<p>@sheesh<br />
As for Vista: it still stores passwords as an unsalted hash. Which yes, makes it possible to reverse them in minutes. Look into ophcrack. This has little to do with cryptographic key quality though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/#comment-4685</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Sat, 12 Jul 2008 12:26:02 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.wordpress.com/?p=137#comment-4685</guid>
		<description>We all know it&#039;s easy for Microsoft to stand at the top of the walled fortress and throw off-hand remarks out due to their closed nature, and if this was Microsoft instead of Debian, well no-one would even know.

However, if you are a security focussed company in the Free Software world, you choose Suse or Red Hat or another enterprise-y distribution. Hell, use QNX. People are very quick to say &quot;Oh, you used Free software, it&#039;s not as good as money you paid for.&quot;, you pay for Linux. It&#039;s a profitable operating system, you just don&#039;t HAVE to. 

Just don&#039;t run a high security network on a consumer operating system.</description>
		<content:encoded><![CDATA[<p>We all know it&#8217;s easy for Microsoft to stand at the top of the walled fortress and throw off-hand remarks out due to their closed nature, and if this was Microsoft instead of Debian, well no-one would even know.</p>
<p>However, if you are a security focussed company in the Free Software world, you choose Suse or Red Hat or another enterprise-y distribution. Hell, use QNX. People are very quick to say &#8220;Oh, you used Free software, it&#8217;s not as good as money you paid for.&#8221;, you pay for Linux. It&#8217;s a profitable operating system, you just don&#8217;t HAVE to. </p>
<p>Just don&#8217;t run a high security network on a consumer operating system.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: website design</title>
		<link>http://rdist.root.org/2008/05/19/debian-needs-some-serious-commit-review/#comment-4684</link>
		<dc:creator>website design</dc:creator>
		<pubDate>Fri, 11 Jul 2008 23:43:13 +0000</pubDate>
		<guid isPermaLink="false">http://rdist.wordpress.com/?p=137#comment-4684</guid>
		<description>Saying that the fix isn&#039;t complete is slightly misleading and shows he didn&#039;t quite read enough on the issue. The line that wasn&#039;t uncommented is the one between #ifdef PURIFY, as such, the code is already documented (by upstream) to work without it.</description>
		<content:encoded><![CDATA[<p>Saying that the fix isn&#8217;t complete is slightly misleading and shows he didn&#8217;t quite read enough on the issue. The line that wasn&#8217;t uncommented is the one between #ifdef PURIFY, as such, the code is already documented (by upstream) to work without it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
