[mod.computers.vax] VMS-Security Problems on this list

#D15@DDATHD21.BITNET (11/16/85)

Dear Andy,

     you are right, there are SPR's and the TSC to inform DEC about
serious software problems in VMS and it shouldn't be neccessary to
publish this items on this list.

 The problem is, SPR's and TSC aren't as reliable and fast as you
and other DEC people tell us. From TSC we get often the answer
"We don't know about this problem, it's not in our DATABASE". And
often this problems have been discussed on this list month ago
(like the MTH$DEXP problem in VMS 4.2) and solutions are available
from DEC engineering. Or what shall I do with the SPR-answer "This
problem will be fixed in a future major release" received 5 month
after posting an SPR.

 I think posting serious VMS (and other products) problems to this
list is a good idea. Even system managers of "high security" sites
can benefit from this postings. They can try to find their own
solutions before the hackers try to penetrate their systems.
Without this list they often wouldn't know about this problems
unless it's to late.

 In my opinion the VMS-bugs will appear on the HACKERS-BB anyway,
regardelss if they are posted here or not.

 The only way to keep such postings out seems (for me) to convert
this list to a moderated one. But if this happens, I'll be one of
the first people to leave, because I like/want/need free information
about serious problems.

With kind regards
                  Martin Knoblauch