Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #244636

Re: Security

From Andrei POPESCU <andreimpopescu@gmail.com>
Newsgroups linux.debian.user
Subject Re: Security
Date 2022-01-26 19:40 +0100
Message-ID <DJVn4-4Zi-3@gated-at.bofh.it> (permalink)
References <DJAiB-7jg-3@gated-at.bofh.it> <DJCkq-hG-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Ma, 25 ian 22, 16:13:23, Nate Bargmann wrote:
> I am subscribed to that list and get them too.
> 
> I just see that three more messages popped in since this morning from
> the security list.
> 
> The complaints seem to be only about browsers.  The inference seems to
> be that the latest release always fixes security bugs.  While this is
> true to an extent, what is seldom acknowledged is that new releases also
> bring new and as yet undisclosed bugs that will be fixed next time or
> the time after or the time after that or...  I figure it's a gamble
> either way and stick with the Debian packages.

I'll use the opportunity to draw attention to DSA-5059-1, see e.g. this 
article for details:

https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/

And please don't bother to reply with "there are no other users on this 
system I should worry about", the bad guys could still find ways to get 
in, e.g. via a compromised browser, regardless if you are behind a 
firewall or not[1].

Any system connecting to the internet should be kept up-to-date.

Even if you don't care about your data, privacy, etc., your system will 
probably become part of some botnet and be used to spread malware and 
spam to others.


[1] Of course, the risk level is significantly lower for the typical 
home user, but still not negligible in my opinion - we just can't know 
what unknown browser vulnerabilities there might be lurking, which the 
bad guys could actively exploit via malicious websites (vs. targeted 
attacks for high value targets).

In today's world once your browser is compromised https://xkcd.com/1200/ 
applies.


Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 21:10 +0100
  Re: Security Andy Smith <andy@strugglers.net> - 2022-01-25 21:50 +0100
    Re: Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 22:00 +0100
      Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-26 16:40 +0100
  Re: Security Nate Bargmann <n0nb@n0nb.us> - 2022-01-25 23:20 +0100
    Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-26 19:40 +0100
      Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 04:50 +0100
        Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 14:20 +0100
          Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:20 +0100
            Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 19:00 +0100
        Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-01-28 16:20 +0100
          Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:30 +0100
          Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-01-30 13:40 +0100
            Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 14:20 +0100
              Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-30 14:40 +0100
                Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 17:50 +0100
                Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-02-04 09:50 +0100
                Re: Security Reco <recoverym4n@enotuniq.net> - 2022-02-04 10:20 +0100
                Re: Security <tomas@tuxteam.de> - 2022-02-04 10:20 +0100
            Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-01 12:30 +0100
              Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-02-02 02:00 +0100
                Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-02 15:10 +0100
        Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-28 17:30 +0100

csiph-web