[vox-tech] can YOU be certified?!?

Rick Moen vox-tech@lists.lugod.org
Mon, 22 Jul 2002 00:25:18 -0700


Quoting Ryan (ryan@mother.com):

> I also noticed that there's a cash prize for security holes, which has
> yet to be claimed. 

The offer makes some perfectly understandable exclusions.  (DJB &
supporters certainly wouldn't want to give money for problems arising
elsewhere in the system, or from careless administration.)  Among them
is a fairly broad category, in clause #9:  "Exploits based on insecure
customized configuration beyond the minimal install...."

Now, I'm not suggesting in any way that DJB & friends are copping out.
Far from it.  However, I know from my own experience that any heavily
used qmail site ends up needing significant customisations _and_
patches.  Which quickly prevents you from having a qualifying system.