From: Hans Reiser <reiser@namesys.com>
To: Ripin Natani <rnatani@platformlogic.com>
Cc: reiserfs <reiserfs-list@namesys.com>
Subject: Re: Revised Question About Security ...
Date: Tue, 17 Jun 2003 14:19:46 +0400 [thread overview]
Message-ID: <3EEEEB42.3010003@namesys.com> (raw)
In-Reply-To: <00d101c33422$92c60810$3b0aa8c0@yourn3ty7athd5>
Ripin Natani wrote:
>Hi,
> Regarding the question about security, What I really want is :
>1. Are there any current security issues in reiserfs ?
>
No.
>2. Is there a listing or history of security issues that I can access and
>review? Can you point me to them ?
>
We had one bug quite some time ago. The guy who found it was of the "I
want to shout my name rather than quietly tell the vendor variety" that
so afflicts our industry. It was fixed at the speed we fix all bugs
(maybe sameday, maybe as much as 3 days, I forget now). There was some
discussion about whether it was really a security bug which I no longer
remember.
Of course you should remember that lots of ordinary bugs can be
considered security bugs if you look at them carefully. This was the
only one that was identified by the reporter as a security bug.
ReiserFS in general is committed to having a zero defect product, and to
fixing 97%+ of reproducible bugs in 3 days or less. The <3% usually
consist of bugs that are hard to reproduce often enough to debug
effectively. Deep bugs requiring large amounts of code are fortunately
very very rare.
>3. In your knowledge, how would reiserfs be less or more secure than say, ext2 ?
>
Ignoring release management issues, it would be the same, at least until
V4 comes out. For details on v4, read www.namesys.com/v4/v4.html. In
regards to release management, one perhaps significant advantage we
might have is that ReiserFS V3 is changing less because we are all
working on V4, and we don't allow people other than Chris (who is
outside my management sphere) to submit patches that have not been read
and tested by two persons.
We are now able to go for months without a valid bug reported.
>
>Thanks,
>-Ripin.
>
>
>
>
--
Hans
prev parent reply other threads:[~2003-06-17 10:19 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-06-16 16:15 Revised Question About Security Ripin Natani
2003-06-17 10:19 ` Hans Reiser [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3EEEEB42.3010003@namesys.com \
--to=reiser@namesys.com \
--cc=reiserfs-list@namesys.com \
--cc=rnatani@platformlogic.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.