<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Open Source Software &#8211; a Chink in the Armour</title>
	<atom:link href="http://blog.simpleigh.com/2008/05/open-source-software-a-chink-in-the-armour/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.simpleigh.com/2008/05/open-source-software-a-chink-in-the-armour/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Tue, 20 May 2008 10:56:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Richard Smith</title>
		<link>http://blog.simpleigh.com/2008/05/open-source-software-a-chink-in-the-armour/comment-page-1/#comment-228</link>
		<dc:creator>Richard Smith</dc:creator>
		<pubDate>Tue, 20 May 2008 10:56:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.simpleigh.com/2008/05/open-source-software-a-chink-in-the-armour/#comment-228</guid>
		<description>&quot;Firstly, vendors should not be fixing problems (or, really, anything) in open source packages by patching them locally - they should contribute their patches upstream to the package maintainers. Had Debian done this in this case, we (the OpenSSL Team) would have fallen about laughing, and once we had got our breath back, told them what a terrible idea this was.&quot;

Well, the error was introduced into Debian on 2nd May 2006 by Kurk Roeckx in this commit:

http://svn.debian.org/viewsvn/pkg-openssl/openssl/trunk/rand/md_rand.c?rev=141&amp;r1=140&amp;r2=141

The previous day, he posted an email to the openssl-dev list asking whether this patch would be sensible:

http://marc.info/?l=openssl-dev&amp;m=114651085826293&amp;w=2

A few hours later, Ulf Möller responded that he was in favour of the patch.

http://marc.info/?l=openssl-dev&amp;m=114652287210110&amp;w=2

According to the OpenSSL webpage, Ulf Möller is a member of the OpenSSL development team:

http://openssl.org/about/

... and has been for quite a some time

http://web.archive.org/web/20000815074639/www.openssl.org/about/

I wonder whether the OpenSSL team are still &quot;falling around laughing&quot;.</description>
		<content:encoded><![CDATA[<p>&#8220;Firstly, vendors should not be fixing problems (or, really, anything) in open source packages by patching them locally &#8211; they should contribute their patches upstream to the package maintainers. Had Debian done this in this case, we (the OpenSSL Team) would have fallen about laughing, and once we had got our breath back, told them what a terrible idea this was.&#8221;</p>
<p>Well, the error was introduced into Debian on 2nd May 2006 by Kurk Roeckx in this commit:</p>
<p><a href="http://svn.debian.org/viewsvn/pkg-openssl/openssl/trunk/rand/md_rand.c?rev=141&#038;r1=140&#038;r2=141" rel="nofollow">http://svn.debian.org/viewsvn/pkg-openssl/openssl/trunk/rand/md_rand.c?rev=141&#038;r1=140&#038;r2=141</a></p>
<p>The previous day, he posted an email to the openssl-dev list asking whether this patch would be sensible:</p>
<p><a href="http://marc.info/?l=openssl-dev&#038;m=114651085826293&#038;w=2" rel="nofollow">http://marc.info/?l=openssl-dev&#038;m=114651085826293&#038;w=2</a></p>
<p>A few hours later, Ulf Möller responded that he was in favour of the patch.</p>
<p><a href="http://marc.info/?l=openssl-dev&#038;m=114652287210110&#038;w=2" rel="nofollow">http://marc.info/?l=openssl-dev&#038;m=114652287210110&#038;w=2</a></p>
<p>According to the OpenSSL webpage, Ulf Möller is a member of the OpenSSL development team:</p>
<p><a href="http://openssl.org/about/" rel="nofollow">http://openssl.org/about/</a></p>
<p>&#8230; and has been for quite a some time</p>
<p><a href="http://web.archive.org/web/20000815074639/www.openssl.org/about/" rel="nofollow">http://web.archive.org/web/20000815074639/www.openssl.org/about/</a></p>
<p>I wonder whether the OpenSSL team are still &#8220;falling around laughing&#8221;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

