<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Too similar to be different</title>
	<atom:link href="http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/</link>
	<description>Mindblogging the world to itself</description>
	<pubDate>Thu, 20 Nov 2008 17:01:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: wheestAttalia</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-272424</link>
		<dc:creator>wheestAttalia</dc:creator>
		<pubDate>Fri, 14 Nov 2008 06:29:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-272424</guid>
		<description>god site. it was very interestingly</description>
		<content:encoded><![CDATA[<p>god site. it was very interestingly</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Zooxyhusy</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-269051</link>
		<dc:creator>Zooxyhusy</dc:creator>
		<pubDate>Sat, 08 Nov 2008 03:16:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-269051</guid>
		<description>Hello! Good site, good content</description>
		<content:encoded><![CDATA[<p>Hello! Good site, good content</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MutOffegeNefe</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-268975</link>
		<dc:creator>MutOffegeNefe</dc:creator>
		<pubDate>Sat, 08 Nov 2008 00:25:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-268975</guid>
		<description>Good site! Successes in future</description>
		<content:encoded><![CDATA[<p>Good site! Successes in future</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lanux &#187; Vulnerabilidad de OpenSSL en Debian</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-141362</link>
		<dc:creator>Lanux &#187; Vulnerabilidad de OpenSSL en Debian</dc:creator>
		<pubDate>Tue, 20 May 2008 13:57:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-141362</guid>
		<description>[...] dejo mis links [...]</description>
		<content:encoded><![CDATA[<p>[...] dejo mis links [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ciol</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136894</link>
		<dc:creator>ciol</dc:creator>
		<pubDate>Thu, 15 May 2008 21:53:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136894</guid>
		<description>I honestly cannot see the correlation between patching things for integration or the /size of stable/ on this problem.

The patches against ssh should have been reviewed by /more than one person/ in the last few year

...</description>
		<content:encoded><![CDATA[<p>I honestly cannot see the correlation between patching things for integration or the /size of stable/ on this problem.</p>
<p>The patches against ssh should have been reviewed by /more than one person/ in the last few year</p>
<p>&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136616</link>
		<dc:creator>Jon</dc:creator>
		<pubDate>Thu, 15 May 2008 09:58:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136616</guid>
		<description>I honestly cannot see the correlation between patching things for integration or the size of stable on this problem.

The patches against ssh should have been reviewed by more than one person in the last few years, yes, there have definitely been errors here. But I don't see how this extrapolates to the entire archive.

That sounds like slashdot sound-byte nonsense.</description>
		<content:encoded><![CDATA[<p>I honestly cannot see the correlation between patching things for integration or the size of stable on this problem.</p>
<p>The patches against ssh should have been reviewed by more than one person in the last few years, yes, there have definitely been errors here. But I don&#8217;t see how this extrapolates to the entire archive.</p>
<p>That sounds like slashdot sound-byte nonsense.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mac</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136394</link>
		<dc:creator>Mac</dc:creator>
		<pubDate>Thu, 15 May 2008 02:18:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136394</guid>
		<description>Very well done article on a not so easy topic. It's ok if there are folks out there who disagree. That is their 'bug' to fix not mine. ;-) I use Debian today. No changes are planned.</description>
		<content:encoded><![CDATA[<p>Very well done article on a not so easy topic. It&#8217;s ok if there are folks out there who disagree. That is their &#8216;bug&#8217; to fix not mine. <img src='http://www.aigarius.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> I use Debian today. No changes are planned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erich</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136053</link>
		<dc:creator>Erich</dc:creator>
		<pubDate>Wed, 14 May 2008 19:34:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136053</guid>
		<description>Hi,
Just a quick followup. The main location where this warning of using "uninitialized memory" does indeed deliberately use uninitialized memory. The function is expected to fill a buffer with random data. It first uses the current memory contents to further randomize (maybe, if that data is random), then fills the buffer with randomness.
This use of the existing contents is definitely safe and doesn't do any harm (except causing this warning, which sparked all this mess, actually...)

The big mistake the Debian maintainer did was to also remove another *literate* copy of that line in the OpenSSL source, which happened to be used to feed randomness into the RNG, thus making all OpenSSL efforts to obtain more randomness moot.

The reason why I believe OpenSSL upstream is also to blame is because they didn't care about other users wanting to use valgrind and not see their "deliberate" error reported again and again. This caused the Debian maintainer to fix the issue himself, introducing the mistake. If OpenSSL had cared about developers wanting to use valgrind, it wouldn't have happened in the first place.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
Just a quick followup. The main location where this warning of using &#8220;uninitialized memory&#8221; does indeed deliberately use uninitialized memory. The function is expected to fill a buffer with random data. It first uses the current memory contents to further randomize (maybe, if that data is random), then fills the buffer with randomness.<br />
This use of the existing contents is definitely safe and doesn&#8217;t do any harm (except causing this warning, which sparked all this mess, actually&#8230;)</p>
<p>The big mistake the Debian maintainer did was to also remove another *literate* copy of that line in the OpenSSL source, which happened to be used to feed randomness into the RNG, thus making all OpenSSL efforts to obtain more randomness moot.</p>
<p>The reason why I believe OpenSSL upstream is also to blame is because they didn&#8217;t care about other users wanting to use valgrind and not see their &#8220;deliberate&#8221; error reported again and again. This caused the Debian maintainer to fix the issue himself, introducing the mistake. If OpenSSL had cared about developers wanting to use valgrind, it wouldn&#8217;t have happened in the first place.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ciol</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136033</link>
		<dc:creator>ciol</dc:creator>
		<pubDate>Wed, 14 May 2008 18:28:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-136033</guid>
		<description>"It doesn't matter how often you do it: freezing thousands of packages into a stasis just doesn't work." tuomov, 03/03/2007. He was right.

As a /. user says "who cares how "integrated" a program is, if it could have had arbitrary bugs silently introduced?"

Debian's packages are /too/ well integrated.

If -stable was smaller, maybe this would have not happened.</description>
		<content:encoded><![CDATA[<p>&#8220;It doesn&#8217;t matter how often you do it: freezing thousands of packages into a stasis just doesn&#8217;t work.&#8221; tuomov, 03/03/2007. He was right.</p>
<p>As a /. user says &#8220;who cares how &#8220;integrated&#8221; a program is, if it could have had arbitrary bugs silently introduced?&#8221;</p>
<p>Debian&#8217;s packages are /too/ well integrated.</p>
<p>If -stable was smaller, maybe this would have not happened.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rudi Cilibrasi, PhD</title>
		<link>http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-135985</link>
		<dc:creator>Rudi Cilibrasi, PhD</dc:creator>
		<pubDate>Wed, 14 May 2008 16:12:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.aigarius.com/blog/2008/05/14/too-similar-to-be-different/#comment-135985</guid>
		<description>As I tried to explain, the logic in this entry was flawed.  See correct logic at the following URL:

http://www.links.org/?p=328</description>
		<content:encoded><![CDATA[<p>As I tried to explain, the logic in this entry was flawed.  See correct logic at the following URL:</p>
<p><a href="http://www.links.org/?p=328" rel="nofollow">http://www.links.org/?p=328</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
