version 1.110, 1999/09/22 18:33:46 |
version 1.111, 1999/09/23 20:21:23 |
|
|
<a href=#goals>Security goals of the Project</a>.<br> |
<a href=#goals>Security goals of the Project</a>.<br> |
<a href=#disclosure>Full Disclosure policy</a>.<br> |
<a href=#disclosure>Full Disclosure policy</a>.<br> |
<a href=#process>Source code auditing process</a>.<br> |
<a href=#process>Source code auditing process</a>.<br> |
<a href=#process>"Secure by Default"</a>.<br> |
<a href=#default>"Secure by Default"</a>.<br> |
<a href=#crypto>Use of Cryptography</a>.<br> |
<a href=#crypto>Use of Cryptography</a>.<br> |
<p> |
<p> |
<a href=#25>For 2.5 security advisories</a>.<br> |
<a href=#25>For 2.5 security advisories</a>.<br> |
|
|
turnaround is possible. Thus we think that full disclosure helps the |
turnaround is possible. Thus we think that full disclosure helps the |
people who really care about security.<p> |
people who really care about security.<p> |
|
|
|
<a name=process> |
<li><h3><font color=#e00000>Audit Process</font></h3><p> |
<li><h3><font color=#e00000>Audit Process</font></h3><p> |
|
|
Our security auditing team typically has between six and twelve |
Our security auditing team typically has between six and twelve |
|
|
by default, creating instantaneous security problems for their users |
by default, creating instantaneous security problems for their users |
within minutes after their first install.<p> |
within minutes after their first install.<p> |
|
|
|
<a name=crypto> |
<li><h3><font color=#e00000>Cryptography</font></h3><p> |
<li><h3><font color=#e00000>Cryptography</font></h3><p> |
|
|
And of course, since the OpenBSD project is based in Canada, it is possible |
And of course, since the OpenBSD project is based in Canada, it is possible |
|
|
</ul> |
</ul> |
|
|
<p> |
<p> |
|
<a name=reporting> |
<li><h3><font color=#e00000>Reporting problems</font></h3><p> |
<li><h3><font color=#e00000>Reporting problems</font></h3><p> |
|
|
<p> If you find a new security problem, you can mail it to |
<p> If you find a new security problem, you can mail it to |