|
|
|
|
|
by pilif
3075 days ago
|
|
> But it worked, and the core software stayed secure are you sure? How can you be sure that your custom patches didn't affect the security of the core product? qmail wasn't designed to be extensible. It had no plugin interface. Of course it's possible that you didn't make a mistake back then. Just as it's possible that I didn't make a mistake when I was 18 and wrote a patch to Cyrus imapd to allow authenticating against an SQL database. But TBH, when I look back at the code I wrote back then, at least in my case, I'm quite sure I f'ed up in various ways. Thankfully, I never shared these patches with other people. |
|
It's kind of like using OBSD as your app platform. You can definitely make it insecure! But it's more secure by default than others, perhaps because of a lack of features, as well as very good security design.