3 ms·
It sounds incredibly audacious until you consider the number of security holes discovered in qmail after all these years: one, and it wasn't exploitable on any
by sketerpot 17y ago
It sounds incredibly audacious until you consider the number of security holes discovered in qmail after all these years: one, and it wasn't exploitable on any existing computer system.
- vog 17y agoHow much worth is a secure software if it quickly becomes outdated and thus useless? (at least in its original, secure form) Qmail is an example of how to success in security, but then fail another way. DJB never reviewed contributed features, or reimplemented them the "right/secure way". There was absolutely no plan to evolve Qmail, so it was unable to fit future requirements. This catastrophic project management literally provoked forks and patches. People had to modify the original Qmail to get even basic features such as SMTP authentiation or integration with spam scanners. Many patches of questionable quality are flying around, and no official next version of qmail. So to be fair, we should count the bugs in the Qmail forks (e.g. qmail-ng), because these are the versions that are actually used.