Re: The netsec thread

From: Robert Pluim
Subject: Re: The netsec thread
Date: Mon, 29 Jul 2019 10:11:25 +0200

>>>>> On Mon, 29 Jul 2019 09:50:03 +0200, Robert Pluim <address@hidden> said:

>>>>> On Sun, 28 Jul 2019 21:08:05 +0200, Lars Ingebrigtsen <address@hidden> 
>>>>> said:
    Lars> I've now done some testing of the netsec branch, and it basically 
    Lars> good to me.  It's a bit too detailed in the warnings it presents to 
    Lars> user -- the original idea was to keep the level of detail down so that
    Lars> it won't scare away everyone but security professionals, and it's now
    Lars> rather scary.

    Lars> I've only skimmed the patch set -- it's 2200 lines, but I've got one
    Lars> question to Robert: The patches that add `network-lookup-address-info'
    Lars> went into the netsec branch.  Was there any particular reason for 
    Lars> They seem rather unrelated.  (It does look like a useful addition,
    Lars> though.)

    Robert> I seem to remember Jimmy wanted it so he could add further 
    Robert> checks. He dropped off before he could explain exactly what those
    Robert> were, and they're not necessary for his changes.

Although you could use it to replace his nslookup-host-ipv{4,6}


