<HTML >
<HEAD>
<META http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name=Generator content="Microsoft Word 11 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]--><o:SmartTagType
namespaceuri="urn:schemas-microsoft-com:office:smarttags" name="City"/>
<o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags"
name="country-region"/>
<o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags"
name="place"/>
<!--[if !mso]>
<style>
st1\:*{behavior:url(#default#ieooui) }
</style>
<![endif]-->
<style>
<!--
/* Font Definitions */
@font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:12.0pt;
        font-family:"Times New Roman";}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {color:blue;
        text-decoration:underline;}
pre
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:10.0pt;
        font-family:"Courier New";}
span.EmailStyle18
        {mso-style-type:personal-reply;
        font-family:Arial;
        color:navy;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
        {page:Section1;}
-->
</style>
</HEAD>
<BODY lang=EN-US link=blue vlink=blue>
<DIV>
<div class=Section1>
<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>If it is in the source and you have people
vetting the source it would extremely difficult. I imagine <st1:country-region
w:st="on"><st1:place w:st="on">China</st1:place></st1:country-region> once they
made their “hardened” version of BSD would be using upstream source rather than
ports to do the updates if any.<o:p></o:p></span></font></p>
<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>
<div>
<div class=MsoNormal align=center style='text-align:center'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>
<hr size=2 width="100%" align=center tabindex=-1>
</span></font></div>
<p class=MsoNormal><b><font size=2 face=Tahoma><span style='font-size:10.0pt;
font-family:Tahoma;font-weight:bold'>From:</span></font></b><font size=2
face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'>
ale-bounces@ale.org [mailto:ale-bounces@ale.org] <b><span style='font-weight:
bold'>On Behalf Of </span></b>Richard Faulkner<br>
<b><span style='font-weight:bold'>Sent:</span></b> Wednesday, October 13, 2010
1:35 PM<br>
<b><span style='font-weight:bold'>To:</span></b> Atlanta Linux Enthusiasts -
Yes! We run Linux!<br>
<b><span style='font-weight:bold'>Subject:</span></b> Re: [ale] <st1:country-region
w:st="on"><st1:place w:st="on">China</st1:place></st1:country-region> chooses
FreeBSD as basis for secure OS</span></font><o:p></o:p></p>
</div>
<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><o:p> </o:p></span></font></p>
<p class=MsoNormal style='margin-bottom:12.0pt'><font size=3
face="Times New Roman"><span style='font-size:12.0pt'>Okay...this then brings
up an interesting proposition. Is it possible to build a tenable backdoor
in a distro that would go unnoticed at source code level? For security
purposes would it be better to develop (as a state) your own updates rather
than take distro updates from source? Could this mark a threat to
security as we see it?<br>
<br>
Please keep in mind that I'm new to Linux and NOT a programmer...more of a
designer. <br>
<br>
<br>
-----Original Message-----<br>
<b><span style='font-weight:bold'>From</span></b>: wolf@wolfhalton.info <<a
href="mailto:%22wolf@wolfhalton.info%22%20%3cwolf@wolfhalton.info%3e">wolf@wolfhalton.info</a>><br>
<b><span style='font-weight:bold'>Reply-to</span></b>: <st1:City w:st="on"><st1:place
w:st="on">Atlanta</st1:place></st1:City> Linux Enthusiasts - Yes! We run
Linux! <ale@ale.org><br>
<b><span style='font-weight:bold'>To</span></b>: <a
href="mailto:mhw@wittsend.com">mhw@wittsend.com</a>, Atlanta Linux Enthusiasts
- Yes! We run Linux! <<a
href="mailto:Atlanta%20Linux%20Enthusiasts%20-%20Yes!%20We%20run%20Linux!%20%3cale@ale.org%3e">ale@ale.org</a>><br>
<b><span style='font-weight:bold'>Subject</span></b>: Re: [ale] <st1:country-region
w:st="on"><st1:place w:st="on">China</st1:place></st1:country-region> chooses
FreeBSD as basis for secure OS<br>
<b><span style='font-weight:bold'>Date</span></b>: Tue, 12 Oct 2010 21:35:02
-0400<br>
<br>
It would at least be a little more of a challenge than Window$<br>
<br>
-----Original Message-----<br>
<b><span style='font-weight:bold'>From</span></b>: Michael H. Warfield <<a
href="mailto:%22Michael%20H.%20Warfield%22%20%3cmhw@wittsend.com%3e">mhw@wittsend.com</a>><br>
<b><span style='font-weight:bold'>Reply-to</span></b>: mhw@wittsend.com,
Atlanta Linux Enthusiasts - Yes! We run Linux! <ale@ale.org><br>
<b><span style='font-weight:bold'>To</span></b>: Atlanta Linux Enthusiasts -
Yes! We run Linux! <<a
href="mailto:Atlanta%20Linux%20Enthusiasts%20-%20Yes!%20We%20run%20Linux!%20%3cale@ale.org%3e">ale@ale.org</a>><br>
<b><span style='font-weight:bold'>Cc</span></b>: <a
href="mailto:mhw@wittsend.com">mhw@wittsend.com</a><br>
<b><span style='font-weight:bold'>Subject</span></b>: Re: [ale] <st1:country-region
w:st="on"><st1:place w:st="on">China</st1:place></st1:country-region> chooses
FreeBSD as basis for secure OS<br>
<b><span style='font-weight:bold'>Date</span></b>: Tue, 12 Oct 2010 17:26:40
-0400<o:p></o:p></span></font></p>
<pre><font size=2 face="Courier New"><span style='font-size:10.0pt'><o:p> </o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>On Tue, 2010-10-12 at 15:58 -0400, Chuck Payne wrote: <o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> On Tue, Oct 12, 2010 at 3:13 PM, George Allen <<a
href="mailto:glallen01@gmail.com">glallen01@gmail.com</a>> wrote:<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > Apparently <st1:country-region
w:st="on"><st1:place w:st="on">China</st1:place></st1:country-region> is moving their entire Dept of Defense to a hardened<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > version of FreeBSD.<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > <a
href="http://blogs.techrepublic.com.com/security/?p=1682">http://blogs.techrepublic.com.com/security/?p=1682</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > _______________________________________________<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > Ale mailing list<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > <a
href="mailto:Ale@ale.org">Ale@ale.org</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > <a
href="http://mail.ale.org/mailman/listinfo/ale">http://mail.ale.org/mailman/listinfo/ale</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > See JOBS, ANNOUNCE and SCHOOLS lists at<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> > <a
href="http://mail.ale.org/mailman/listinfo">http://mail.ale.org/mailman/listinfo</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> ><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><o:p> </o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>> Good Choose.<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><o:p> </o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>I presume you meant choice and I concur. Give that some reports are<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>putting the level of Stuxnet infections at over 1 million machines in<o:p></o:p></span></font></pre><pre><st1:country-region
w:st="on"><font size=2 face="Courier New"><span style='font-size:10.0pt'>Iran</span></font></st1:country-region> and more than 6 million machines in <st1:country-region
w:st="on"><st1:place w:st="on">China</st1:place></st1:country-region>, anything, other that<o:p></o:p></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Windows, would be a smooth move. Nobody really knows who is behind the<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Stuxnet but I would put it at 99% probability that it's "state<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>sponsored" and the leading contenders are <st1:country-region
w:st="on">Israel</st1:country-region>, the <st1:country-region w:st="on">US</st1:country-region>, and <st1:country-region
w:st="on"><st1:place w:st="on">Russia</st1:place></st1:country-region>.<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Unfortunately, any of those players are more than capable of building<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>something nasty for FreeBSD or Linux, or even OpenBSD if they really set<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>their minds to it.<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><o:p> </o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Regards,<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Mike<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>_______________________________________________<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Ale mailing list<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><a
href="mailto:Ale@ale.org">Ale@ale.org</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><a
href="http://mail.ale.org/mailman/listinfo/ale">http://mail.ale.org/mailman/listinfo/ale</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>See JOBS, ANNOUNCE and SCHOOLS lists at<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><a
href="http://mail.ale.org/mailman/listinfo">http://mail.ale.org/mailman/listinfo</a><o:p></o:p></span></font></pre>
<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><o:p> </o:p></span></font></p>
<pre><font size=2 face="Courier New"><span style='font-size:10.0pt'><o:p> </o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>_______________________________________________<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>Ale mailing list<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><a
href="mailto:Ale@ale.org">Ale@ale.org</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><a
href="http://mail.ale.org/mailman/listinfo/ale">http://mail.ale.org/mailman/listinfo/ale</a><o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'>See JOBS, ANNOUNCE and SCHOOLS lists at<o:p></o:p></span></font></pre><pre><font
size=2 face="Courier New"><span style='font-size:10.0pt'><a
href="http://mail.ale.org/mailman/listinfo">http://mail.ale.org/mailman/listinfo</a><o:p></o:p></span></font></pre>
<p class=MsoNormal><font size=3 face="Times New Roman"><span style='font-size:
12.0pt'><o:p> </o:p></span></font></p>
</div>
</DIV>
<DIV> </DIV>
<DIV>
<FONT FACE="Arial" SIZE="2">Proud partner. Susan G. Komen for the Cure.</FONT>
</DIV>
<DIV> </DIV>
<DIV>
<FONT FACE="Arial" COLOR="green" SIZE="1"><EM>Please consider our environment before printing this e-mail or attachments.</EM></FONT>
</DIV>
<DIV STYLE="FONT-SIZE: 9pt; FONT-FAMILY: Courier New">
<FONT FACE="Arial" SIZE="2">----------------------------------<BR>CONFIDENTIALITY NOTICE: This e-mail may contain privileged or confidential information and is for the sole use of the intended recipient(s). If you are not the intended recipient, any disclosure, copying, distribution, or use of the contents of this information is prohibited and may be unlawful. If you have received this electronic transmission in error, please reply immediately to the sender that you have received the message in error, and delete it. Thank you.<BR>----------------------------------<BR></FONT>
</DIV></BODY></HTML>