Should Dan post full details of his tty bugs?

Jyrki Kuoppala jkp at cs.HUT.FI
Mon May 6 21:15:40 AEST 1991


In article <4May91.201446.4564 at franklin.com>, bill at franklin (bill) writes:
>You are in a fool's paradise. At least one of your undergrads is 
>smart enough to figure out what to do with the hole given the 
>clues already posted and to cover himself after using it. For as 
>long as you remain ignorant of the details, you are prevented from
>taking preventative action.

In a situation like this, the first question that comes to my mind is
'Is there any reason the udergrad won't show you the program (s)he
comes up with?'

And what's so horrifying about these undergrads using some common
holes anyway ?  They're supposed to learn something at the Uni, I
think, not supposed to be there to spy for the (insert your favorite
intelligence organization) or terrorize everyone else.

If your university atmosphere for whatever reason is filled with so
much hatred and so little will for cooperation that your users won't
tell you about the problems (with the benefit of getting to learn more
and discuss the problem with people knowing perhaps more of the
problems, to learn more) but instead they cause trouble to other
users, your university is in much more serious trouble than some lousy
computer security.

But then, nowadays when the counterproductive 'rules' and
'regulations' make just about anything or even thinking about it
illegal or seriously punishable, perhaps it's understandable that the
poor students are not willing to risk lawsuits or other penalties by
sharing their information with others.  I don't know, I certainly did
tell about the holes to the administrators but back then our Uni
didn't have all these myriads of written regulations with all kinds of
threats.

//Jyrki



More information about the Comp.unix.wizards mailing list