Received: from localhost (daemon@localhost) by CS.UTK.EDU with SMTP (cf v2.9s-UTK) id RAA08419; Fri, 24 May 1996 17:12:29 -0400 Received: by CS.UTK.EDU (bulk_mailer v1.6); Fri, 24 May 1996 17:12:15 -0400 Received: from koobera.math.uic.edu (qmailr@KOOBERA.MATH.UIC.EDU [128.248.178.247]) by CS.UTK.EDU with SMTP (cf v2.9s-UTK) id RAA08380; Fri, 24 May 1996 17:12:13 -0400 Received: (qmail-queue invoked by uid 666); 24 May 1996 21:15:14 -0000 Date: 24 May 1996 21:15:14 -0000 Message-ID: <19960524211514.2545.qmail@koobera.math.uic.edu> From: djb@koobera.math.uic.edu (D. J. Bernstein) To: drums@cs.utk.edu Subject: Re: 821bis outstanding issues list > Besides, this thing is security through obscurity. It's a deterrent. If sendmail didn't spray version numbers all over the place, an outside attacker wouldn't be able to tell the difference between sendmail 8.6.12 and sendmail 8.6.13---except by trying to exploit the most recent security hole, which would leave an ineradicable trail on many 8.6.13 hosts. ---Dan