[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Announcing Bellcore's Trusted Software Integrity (Betsi) System




> "L. Todd Masco" <[email protected]> writes:
> Certainly not enough to justify the rest: Can you name one example of an
> author of a package including some virus?  Not someone putting one

Yes.

> post-production (individual signing will prevent that), but the original
> author?

Mark Ludwig wrote KOH, an on-the-fly disk encryption program that is also
a virus.  It was posted recently to alt.security.pgp.  Ludwig is the author
of a number of other viruses that don't claim to be useful.

> It's a straw man.

OK.  For the record, I think it's a Good Thing to have as much confidence
in lots of different frequent-version programs as I do in (say) PGP with
its signed-file protocols.

	Jim Gillogly
	Hevensday, 7 Halimath S.R. 1994, 22:32