Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243467
| From | "Andrew M.A. Cater" <amacater@einval.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: debian.org/security is wrong to say what it does |
| Date | 2021-12-26 23:00 +0100 |
| Message-ID | <DyJIB-5Rz-7@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <Dygnf-4Im-1@gated-at.bofh.it> <Dyob8-13S-5@gated-at.bofh.it> <DypAd-22L-3@gated-at.bofh.it> <DyAOZ-pb-1@gated-at.bofh.it> <DyItb-5at-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Sun, Dec 26, 2021 at 09:36:47PM +0100, maxwillb wrote: > December 26, 2021 1:25:30 PM CET "Andrew M.A. Cater" <amacater@einval.com> wrote: > > > but that doesn't mean that everything marked as vulnerable is still at risk. > Hi maxwillb I've tried to explain what I understand by the security tracker. The security tracker is based on sid / Debian unstable and if it is fixed in Sid, it's marked as such and others are automatically marked as vulnerable. That doesn't mean to say that each distribution point marked as vulnerable remains vulnerable throughout the life of the distribution: maintainers are constantly fixing stuff. > I couldn't understand what you meant, and figured you were referring to some extra hardening done by Debian. Did some googling, and apparently, it's the opposite. Debian disables Chromium's own hardening? > > https://www.whonix.org/wiki/Dev/Chromium#Chromium_Debian_Package_Security Whonix is itself based on Debian. Each distribution does its own thing. If you are not sure on what is patched or why, maintainers can probably tell you. Just reading patch sets very quickly there are bits that don't need to be included. If the only "official" build of Chromium comes from Google/Alphabet, then it's not for Debian to set that, for example, and Debian doesn't build for Android. > > """ > Thus, the Debian Chromium has substantially worsened > security than an official version. However, despite this, > it may still be more secure than Firefox (Firefox never > had many of the disabled mitigations in the first place). > """ > > > If you're unhappy with data presentation, feel free to contact the security team > > Am I the only one unhappy with it? Are you happy with it? > I'm not particularly unhappy with it and not as upset as you appear to be. I hang around here to try and help users: I publish the monthly FAQ but I'm not necessarily authoritative and my opinions can always be very wrong. I think I've probably said enough on this topic: I'd hoped to be more clear but it's obvious to me that it is probably not productive for me to labour the point further. Happy to help where I can, however. With every good wish, as ever, Andy Cater > -- > Sent with https://mailfence.com > Secure and private email >
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 00:20 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? Dan Ritter <dsr@randomstring.org> - 2021-12-25 13:50 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 17:20 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-25 14:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 15:40 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-26 00:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:10 +0100
debian.org/security is wrong to say what it does maxwillb <maxwillb@mailfence.com> - 2021-12-26 01:30 +0100
Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 13:30 +0100
Re: debian.org/security is wrong to say what it does maxwillb <maxwillb@mailfence.com> - 2021-12-26 21:40 +0100
Re: debian.org/security is wrong to say what it does "Andrew M.A. Cater" <amacater@einval.com> - 2021-12-26 23:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? Andy Smith <andy@strugglers.net> - 2021-12-25 16:10 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 17:00 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:20 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 17:40 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? <tomas@tuxteam.de> - 2021-12-25 17:50 +0100
Re: How to see the list of CRITICALLY vulnerable packages in Debian? maxwillb <maxwillb@mailfence.com> - 2021-12-25 18:50 +0100
csiph-web