Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Secure VPN Gateway a new solution to InterNet Security

 
Thread Tools Search this Thread
Old 06-09-2006, 02:29 PM   #21
Default Re: Secure VPN Gateway a new solution to InterNet Security


On 2006-06-06, David Gempton <> wrote:
[...]
> My reason for posting to these three news groups is that they all
> focus on Computer security issues. I hoped that members of these
> groups would also be focused on security, rather than GPL trivia.


Copyright infringement and (lack of) license compliance in a product
that you are selling is "trivia"?

--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.


Darren Tucker
  Reply With Quote
Old 06-09-2006, 06:06 PM   #22
Nico Kadel-Garcia
 
Posts: n/a
Default Re: Secure VPN Gateway a new solution to InterNet Security
Darren Tucker wrote:
> On 2006-06-06, David Gempton <> wrote:
> [...]
>> My reason for posting to these three news groups is that they all
>> focus on Computer security issues. I hoped that members of these
>> groups would also be focused on security, rather than GPL trivia.

>
> Copyright infringement and (lack of) license compliance in a product
> that you are selling is "trivia"?


Don't forget the lack of usable documentation, installation instructions,
and source code.




Nico Kadel-Garcia
  Reply With Quote
Old 06-12-2006, 05:37 AM   #23
David Gempton
 
Posts: n/a
Default Re: Secure VPN Gateway a new solution to InterNet Security
Nico Kadel-Garcia wrote:
> Darren Tucker wrote:
>
>>On 2006-06-06, David Gempton <> wrote:
>>[...]
>>
>>>My reason for posting to these three news groups is that they all
>>>focus on Computer security issues. I hoped that members of these
>>>groups would also be focused on security, rather than GPL trivia.

>>
>>Copyright infringement and (lack of) license compliance in a product
>>that you are selling is "trivia"?

>
>
> Don't forget the lack of usable documentation, installation instructions,
> and source code.
>
>

Nico,

I must thank you for your firm encouragement to get the licensing issues sorted out. I
believe that I'm now well on the way to having it properly GPL licensed.

I say "on the way" because at this stage nobody has reviewed my efforts to make everything
comply with GPL Version 2.

One of my concerns was around the distribution of SmoothWall Express 2.0 as a Vmware
virtual machine. So far the SmoothWall community have said that this is not in breach of
their Free Software License.

The documentation is going to be an ongoing project. I am now starting to receive e-mails
from some people that are using the software and this has highlighted areas where I have
not documented things well enough.

As always you can download the Secure VPN Gateway from http://www.ttc4it.co.nz/vpn/index.html

Many thanks
David Gempton.


David Gempton
  Reply With Quote
Old 06-12-2006, 12:47 PM   #24
Nico Kadel-Garcia
 
Posts: n/a
Default Re: Secure VPN Gateway a new solution to InterNet Security
David Gempton wrote:
> Nico Kadel-Garcia wrote:
>> Darren Tucker wrote:
>>
>>> On 2006-06-06, David Gempton <> wrote:
>>> [...]
>>>
>>>> My reason for posting to these three news groups is that they all
>>>> focus on Computer security issues. I hoped that members of these
>>>> groups would also be focused on security, rather than GPL trivia.
>>>
>>> Copyright infringement and (lack of) license compliance in a product
>>> that you are selling is "trivia"?

>>
>>
>> Don't forget the lack of usable documentation, installation
>> instructions, and source code.
>>
>>

> Nico,
>
> I must thank you for your firm encouragement to get the licensing
> issues sorted out. I believe that I'm now well on the way to having
> it properly GPL licensed.


Firm encouragement? I thought I was chastising you. But getting the GPL
straightened out is a big deal.

> I say "on the way" because at this stage nobody has reviewed my
> efforts to make everything comply with GPL Version 2.


That's because you haven't published source code, unless you've stuffed it
all inside that VMware module, and no one sane is going to install that
without some better breakdown of what it does and what's in it. VMware
installations can trash your system but hard! As such, they

> One of my concerns was around the distribution of SmoothWall Express
> 2.0 as a Vmware virtual machine. So far the SmoothWall community have
> said that this
> is not in breach of their Free Software License.


But didn't you modify it? Where is your source code if you did? And where is
the acknowledgement in your documentation of the source for the software, if
you didn't modify it? And who exactly are you referring to as "the
SmoothWall community"? It had better include some of the actual authors, or
their lawyers, not just some mailing list members!

This newsgroup from which I'm writing, comp.security.ssh, is unusual in that
it has actual authors of OpenSSH and other utuilities on it. But you
shouldn't take a random post from, say, *ME* as any kind of software
copyright permission, and I hope you're being more careful with those legal
issues than you were in your public claim of "Absolutely Secure" software.
Seriously!

> The documentation is going to be an ongoing project. I am now
> starting to receive e-mails from some people that are using the
> software and this has highlighted areas where I have not documented things
> well enough.


They shouldn't have to be writing this stuff! A simple white paper on how it
works, and most especially the source code, would allow people to give some
of that feedback you crave. But asking the OpenSSH community especially to
review and report on the feasibility of man-in-the-middle attacks without
even a white paper to work from is.... nuts.

> As always you can download the Secure VPN Gateway from
> http://www.ttc4it.co.nz/vpn/index.html
> Many thanks
> David Gempton.


And the documentation is still pitiful, although it's beginning to improve.
Instead of hiding the various files in the http://www.ttc4it.co.nz/download/
directory and only accessing them web links from elsewhere, why not make
that directory browseable? That way, the PDF's and binaries you put there
can be accessed without your having to organize and maintain links to them?

Look, David, I've got nothing personal against you or your development
efforts. The fact that you're posting here is an indication that you're
actually trying to get your stuff working: But that lack of source code is
killing your credibility, in my personal opinion. It's one of the factors
you've simply not properly addressed. Many of the best modern security
tools, like OpenSSH and Triipwire and SELinux, rely heavily on their public
nature to point out potential vulnerabilities. You've apparently ignored
that and kept your code private, even though you apparently also built it on
top of GPL based tools such as SmoothWall Express. That's not just
dangerous, it's insulting to open source developers.

If you won't share your code, why should they share their valuable time
reviewing your product?




Nico Kadel-Garcia
  Reply With Quote
Reply

« Spying ISP | test »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't connect Gateway Laptop to wireless internet yash General Help Related Topics 0 02-16-2008 03:36 PM
Computer Security Information and What You Can Do To Keep Your SystemSafe! Ann.Anderson.group.com@gmail.com A+ Certification 0 12-06-2007 01:55 AM
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
Norton Internet Security 2007 Reviewed @ BIOS Silverstrand Front Page News 0 11-02-2006 02:10 AM
Internet Security - A real test A A+ Certification 4 06-05-2005 06:55 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46