/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to intro.xml

  • Committer: Teddy Hogeborn
  • Date: 2016-08-06 00:53:13 UTC
  • Revision ID: teddy@recompile.se-20160806005313-q9n4b1b7707hnjj4
Makefile: Replace "-fsanitize=address" with "-fsanitize=leak"

The Address Sanitizer is a debugging feature, not a security feature -
it has security issues:  <http://seclists.org/oss-sec/2016/q1/363>
Therefore, it should only be used when debugging.  Replace it with
"-fsanitize=leak", which is needed since -fsanitize=address no longer
includes it implicitly.

* Makefile (DEBUG): Add "-fsanitize=address".
  (ALL_SANITIZE_OPTIONS): Replace "-fsanitize=address" with
                          "-fsanitize=leak".

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY TIMESTAMP "2014-06-22">
 
4
<!ENTITY TIMESTAMP "2016-03-22">
5
5
<!ENTITY % common SYSTEM "common.ent">
6
6
%common;
7
7
]>
32
32
    <copyright>
33
33
      <year>2011</year>
34
34
      <year>2012</year>
 
35
      <year>2013</year>
 
36
      <year>2014</year>
 
37
      <year>2015</year>
 
38
      <year>2016</year>
35
39
      <holder>Teddy Hogeborn</holder>
36
40
      <holder>Björn Påhlsson</holder>
37
41
    </copyright>
197
201
      </para>
198
202
    </refsect2>
199
203
    
 
204
    <refsect2 id="sniff">
 
205
      <title>How about sniffing the network traffic and decrypting it
 
206
      later by physically grabbing the Mandos client and using its
 
207
      key?</title>
 
208
      <para>
 
209
        We only use <acronym>PFS</acronym> (Perfect Forward Security)
 
210
        key exchange algorithms in TLS, which protects against this.
 
211
      </para>
 
212
    </refsect2>
 
213
    
200
214
    <refsect2 id="physgrab">
201
215
      <title>Physically grabbing the Mandos server computer?</title>
202
216
      <para>
365
379
    </para>
366
380
  </refsect1>
367
381
  
 
382
  <refsect1 id="bugs">
 
383
    <title>BUGS</title>
 
384
    <xi:include href="bugs.xml"/>
 
385
  </refsect1>
 
386
  
368
387
  <refsect1 id="see_also">
369
388
    <title>SEE ALSO</title>
370
389
    <para>
398
417
    <variablelist>
399
418
      <varlistentry>
400
419
        <term>
401
 
          <ulink url="http://www.recompile.se/mandos">Mandos</ulink>
 
420
          <ulink url="https://www.recompile.se/mandos">Mandos</ulink>
402
421
        </term>
403
422
        <listitem>
404
423
          <para>