Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 11:57 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 22 posts ]  Go to page Previous  1, 2, 3
Author Message
PostPosted: Tue Feb 10, 2009 8:51 pm 
Offline

Joined: Fri Jun 20, 2008 2:59 am
Posts: 84
zzap wrote:
Not to harp on this, but I am concerned no one from Yubico bothers to address my concerns. Is there really no interest from Yubico's side in explaining why the source code changes were made in the way they were?


I'm not from yubico, but I read and don't understand your concerns exactly. They check in repo changes as they are made.. I don't think that the source code repository is intended as a product of commercial quality, but rather a tool for the community.

I could be wrong.


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Sun Feb 15, 2009 8:44 am 
Offline

Joined: Sat Feb 07, 2009 5:35 pm
Posts: 4
Quote:
I'm not from yubico, but I read and don't understand your concerns exactly. They check in repo changes as they are made.. I don't think that the source code repository is intended as a product of commercial quality, but rather a tool for the community.

I could be wrong.


The Yubico public validation server runs off the key subsystem code in the public repository. The changes to the source that concerned me were made by a Yubico employee.

It's not unreasonable to expect the proper handling of tokens and OTPs in source that is created by the company selling the tokens. It's pretty hard to imagine any other token vendor exposing such borderline cavalier behavior to code correctness.

If you don't understand why the way Yubico deals with this bug -- its initial introduction by quick-and-dirty untested code changes and its subsequent attempt to fix by equally untested code change and complete silence on these facts when challenged -- is very dangerous, then I'm sorry but you don't understand enough about security and should be looking for a different solution.

Unless the Yubikey is just a toy, in which case shame on me for thinking otherwise.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 22 posts ]  Go to page Previous  1, 2, 3

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group