Overview
Examples
Screenshots
Comparisons
Applications
Download
Documentation
Tutorials
Bazaar
Status & Roadmap
FAQ
Authors & License
Forums
Funding Ultimate++
Search on this site
Search in forums












SourceForge.net Logo
Home » Community » Coffee corner » About Linux distros and incompatibilty...
Re: Final release [message #17033 is a reply to message #17031] Fri, 25 July 2008 21:04 Go to previous messageGo to previous message
guido is currently offline  guido
Messages: 169
Registered: April 2006
Experienced Member
Zardos wrote on Fri, 25 July 2008 20:35

You have to wait for the mercy of the god like package maintainers until you can get an update


Not god like, rather like wardens.
People with no real skills in position of relative power.
The claim is added value by enhanced security and "integration".
How well that works we recently saw with the schmuck, who maintains openssl in Debian. He observed uninitialized memory in valgrind. Then went on to comment out the code responsible, with no idea what it does and no upstream talkback. Thereby leaving any Debian server exposed to be be hacked in minutes, for years.
He had removed the entropy gatherer of the ssl key random number generator, reducing the factual range of keys to like 32k.

[Updated on: Fri, 25 July 2008 21:05]

Report message to a moderator

 
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: UPP SW deployment
Next Topic: Win32 UPP console application profiling? Some free easy to use tools, anyone?
Goto Forum:
  


Current Time: Thu Oct 01 18:10:42 CEST 2020

Total time taken to generate the page: 0.01105 seconds