<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: GnuPG Turns 10</title>
	<atom:link href="http://pthree.org/2007/12/20/gnupg-turns-10/feed/" rel="self" type="application/rss+xml" />
	<link>http://pthree.org/2007/12/20/gnupg-turns-10/</link>
	<description>Linux.  GNU.  Freedom.</description>
	<lastBuildDate>Fri, 17 May 2013 20:46:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.6-beta2-24176</generator>
	<item>
		<title>By: Mark A. Hershberger</title>
		<link>http://pthree.org/2007/12/20/gnupg-turns-10/#comment-85316</link>
		<dc:creator>Mark A. Hershberger</dc:creator>
		<pubDate>Thu, 20 Dec 2007 22:36:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.pthree.org/2007/12/20/gnupg-turns-10/#comment-85316</guid>
		<description><![CDATA[Under &lt;a href=&quot;http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000246.html&quot; rel=&quot;nofollow&quot;&gt;GPG&#039;s response to CVE-2006-6235&lt;/a&gt;, Werner Koch writes:
&lt;blockquote cite=&quot;http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000246.html&quot;&gt;However, for reasons of code cleanness and easier audits we will soon start to change all these stack based filter contexts to heap based ones.
&lt;/blockquote&gt;

And another place, he says
&lt;blockquote cite=&quot;http://lwn.net/2000/1019/a/gpg2.php3&quot;&gt;This problem has been in GnuPG since the beginning but Jim seems to be the first one who noticed that. We need better auditing folks!&lt;/blockquote&gt;

So, it looks to me like he is responsive and even proactively changing things (e.g. stack- to heap-based).

The only announcment I found of the fefe patch was &lt;a href=&quot;http://thread.gmane.org/gmane.comp.security.full-disclosure/50542&quot; rel=&quot;nofollow&quot;&gt;on the full disclosure mailing list&lt;/a&gt; and it isn&#039;t clear that he actually notified Werner Koch with a copy of the patch.]]></description>
		<content:encoded><![CDATA[<p>Under <a href="http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000246.html" rel="nofollow">GPG&#8217;s response to CVE-2006-6235</a>, Werner Koch writes:</p>
<blockquote cite="http://lists.gnupg.org/pipermail/gnupg-announce/2006q4/000246.html"><p>However, for reasons of code cleanness and easier audits we will soon start to change all these stack based filter contexts to heap based ones.
</p></blockquote>
<p>And another place, he says</p>
<blockquote cite="http://lwn.net/2000/1019/a/gpg2.php3"><p>This problem has been in GnuPG since the beginning but Jim seems to be the first one who noticed that. We need better auditing folks!</p></blockquote>
<p>So, it looks to me like he is responsive and even proactively changing things (e.g. stack- to heap-based).</p>
<p>The only announcment I found of the fefe patch was <a href="http://thread.gmane.org/gmane.comp.security.full-disclosure/50542" rel="nofollow">on the full disclosure mailing list</a> and it isn&#8217;t clear that he actually notified Werner Koch with a copy of the patch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maks</title>
		<link>http://pthree.org/2007/12/20/gnupg-turns-10/#comment-85260</link>
		<dc:creator>maks</dc:creator>
		<pubDate>Thu, 20 Dec 2007 16:50:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.pthree.org/2007/12/20/gnupg-turns-10/#comment-85260</guid>
		<description><![CDATA[gnugpg should implement better coding style. it is a shame how many security updates it generates and even current state is quite dubious. See for example the fefe auditing that gave no response of Werner Koch.]]></description>
		<content:encoded><![CDATA[<p>gnugpg should implement better coding style. it is a shame how many security updates it generates and even current state is quite dubious. See for example the fefe auditing that gave no response of Werner Koch.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
