On Thursday, October 2, 2003, at 09:00 AM, Chris Olson wrote: > > FYI, anybody who has not updated to 10.2.8 *is* driving an unsafe car > anyway. You're running a computer with a known unpatched > vulnerability. Every other flavour of Unix and Linux have already > dealt with the ssh vulnerability, while those using OS X are still > vulnerable because the patch was included in the update. > > I'm not impressed with that at all. > -- > Chris Well, unlike other companies whose default settings for ports is to leave them on, Apple has the presence of mind not to enable remote login as as a default option. You must manually activate this functionality for it to be a problem in the first place. And if you do, you would also hopefully be aware of its vulnerabilities by now and would have taken measures to guard against it. If you haven't, then that's your fault. Remote login is a fairly advanced feature and to use it would mean that you know more than the average user. Not being impressed is a rather uninformed position. -Neil