[OpenAFS] The Illusion of Security

Derrick J Brashear shadow@dementia.org
Tue, 19 Aug 2003 02:20:24 -0400 (EDT)


On Tue, 19 Aug 2003, Rodney Dyer wrote:

> I do value your opinion.  I'm sorry if I seem to be such a jerk.  I got a
> bit annoyed when I found out that the Sun Solaris kinit supported stdin,
> and I had a knee-jerk reaction.  Some have already replied via personal
> email to my query on the OpenAFS list.  They don't want to get caught up in
> the debate, and I understand.  But they've been positive to my stance
> (unprovable of course because I'll refrain from divulging their names at
> their request out of professional courtesy).

You're free to associate my name with my opinion (please don't associate
anyone else's name with it).

I'm on Sam's side, generally. I suppose recently I did provide a passwd
setting program locally which a Java program is talking to via a pipe. I
was very sad about it, and washed thoroughly afterward. About the only
thing worse would be a command line argument.

While I'm spewing my biases, system("somecommand") instead of using the
API provided to do (whatever) also pushes my buttons.