Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243467

Re: debian.org/security is wrong to say what it does

From "Andrew M.A. Cater" <amacater@einval.com>
Newsgroups linux.debian.user
Subject Re: debian.org/security is wrong to say what it does
Date 2021-12-26 23:00 +0100
Message-ID <DyJIB-5Rz-7@gated-at.bofh.it> (permalink)
References (2 earlier) <Dygnf-4Im-1@gated-at.bofh.it> <Dyob8-13S-5@gated-at.bofh.it> <DypAd-22L-3@gated-at.bofh.it> <DyAOZ-pb-1@gated-at.bofh.it> <DyItb-5at-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Sun, Dec 26, 2021 at 09:36:47PM +0100, maxwillb wrote:
> December 26, 2021 1:25:30 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote:
> 
> > but that doesn't mean that everything marked as vulnerable is still at risk.
> 

Hi maxwillb

I've tried to explain what I understand by the security tracker.

The security tracker is based on sid / Debian unstable and if it is fixed
in Sid, it's marked as such and others are automatically marked as vulnerable.
That doesn't mean to say that each distribution point marked as vulnerable
remains vulnerable throughout the life of the distribution: maintainers
are constantly fixing stuff.

> I couldn't understand what you meant, and figured you were referring to some extra hardening done by Debian. Did some googling, and apparently, it's the opposite. Debian disables Chromium's own hardening?
> 
> https://www.whonix.org/wiki/Dev/Chromium#Chromium_Debian_Package_Security

Whonix is itself based on Debian. Each distribution does its own thing.

If you are not sure on what is patched or why, maintainers can 
probably tell you. Just reading patch sets very quickly there are 
bits that don't need to be included. If the only "official" build of
Chromium comes from Google/Alphabet, then it's not for Debian to set that,
for example, and Debian doesn't build for Android.

> 
> """
> Thus, the Debian Chromium has substantially worsened
> security than an official version. However, despite this,
> it may still be more secure than Firefox (Firefox never
> had many of the disabled mitigations in the first place).
> """
> 
> > If you're unhappy with data presentation, feel free to contact the security team
> 
> Am I the only one unhappy with it? Are you happy with it?
> 

I'm not particularly unhappy with it and not as upset as you appear to be.
I hang around here to try and help users: I publish the monthly FAQ
but I'm not necessarily authoritative and my opinions can always be very
wrong.

I think I've probably said enough on this topic: I'd hoped to be more clear
but it's obvious to me that it is probably not productive for me to labour
the point further. Happy to help where I can, however.

With every good wish, as ever,

Andy Cater

> -- 
> Sent with https://mailfence.com  
> Secure and private email
> 

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 00:20 +0100
  Re: How to see the list of CRITICALLY vulnerable packages in Debian? Dan Ritter <dsr@randomstring.org> - 2021-12-25 13:50 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:20 +0100
  Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-25 14:00 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 15:40 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-26 00:00 +0100
        Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:10 +0100
      debian.org/security is wrong to say what it does maxwillb  <maxwillb@mailfence.com> - 2021-12-26 01:30 +0100
        Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:30 +0100
          Re: debian.org/security is wrong to say what it does maxwillb  <maxwillb@mailfence.com> - 2021-12-26 21:40 +0100
            Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 23:00 +0100
  Re: How to see the list of CRITICALLY vulnerable packages in Debian? Andy Smith <andy@strugglers.net> - 2021-12-25 16:10 +0100
    Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:00 +0100
      Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:20 +0100
        Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 17:40 +0100
          Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:50 +0100
            Re: How to see the list of CRITICALLY vulnerable packages in  Debian? maxwillb  <maxwillb@mailfence.com> - 2021-12-25 18:50 +0100

csiph-web