Re: zip and unzip

Aleksandar Kuktin <[email protected]> Thu, 19 Dec 2019 20:20:50 +0100
Newsgroups gmane.linux.lfs.general
Message-ID <20191219202050.5d911d74@ikilid>
Hi Laura and all!

>On Mon, 16 Dec 2019 08:30:22 -0500
>LM <[email protected]> wrote:

> Was wondering what resources others use to look up security issues and
> fixes.  I typically just check some of the main distributions (like
> Debian) and see what patches they've added to deal with security.
> I'm sure there are better ways to keep up with that type of
> information.  Any recommendations?  Thanks.

A long time ago (2009-2013), I used to read security advisories
(emails) from the Croatian CERT (I was living in Croatia at the time).
They normally referenced CVE, and you almost always had a breadcrumb
trail to a patch you could apply to the code. I remember I would
cumulatively spend an hour or two each week patching my LFS.

But sometime about the end of 2012, the main CVE database started to
get really silent and worthless. You would get an advisory, it would
only reference the CVE ID, but CVE would only tell you the ID is
reserved. It gave absolutely no indication what was going on. So you
literally knew you had *some* vulnerability on your system, but had no
practical way of fixing it.

For a time I tried to fight the system, and would spend several hours
per week wrestling the patches from the Upstream/Internet/Void/Wherever
but it was just too much - I was under a vanishingly small actual real
world risk of having my system actually exploited and the effort simply
got too expensive for that risk (and keeping in mind other things I
could be doing).

I'm still following several distro security advisory lists, still
regularly read the email and *still* tick off the emails for software I
have on my system. But I don't follow through on any of it - too little
time.

Nowdays I rely on architectural security - different computers handle
different grades of sensitive material. *Really* serious stuff is more
or less airgapped, the rest is parceled out to several machines.

I dream of a day when we would run hardware-software meshes that got
formally validated (so you *know* there are no security
vulnerabilities, or any bugs at all anywhere in the system) and then we
wouldn't NEED to patch things, other than for new features, three
times a lifetime. Maybe in 3000 years...

-- 
http://lists.linuxfromscratch.org/listinfo/lfs-chat
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page
signature.asc (application/pgp-signature, 836 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.15 (GNU/Linux)

iQIbBAEBAgAGBQJd+82SAAoJEKa4cgqNx31/3l0P9jwEOl5ZUluPtG8WRWD+6Can
FRZZMXZW+bocOgrY5wAqM6LTfCgPDaBlucTtshIlOrK+Ds9nUo0gwnDT/KQJM0YZ
9EUQm1fDXKkHtxY4CBhdHX7/Dk7xEXyxZv9AI3l+udLYpWhu6IMk3YRH/Fug8/Qv
mSrSEj9u09DxNSbelAHORzAU/H6xV7Q5eP6Qt6XgSDlEVv5jFweflsk6DkRCuJU2
afwDj22xz2czam9SWovNKVJ0+NxV8drll21QUSaUySmz2YEnQAjPQ755hhl8UHCe
T9SO9NTxqfWqELF0iWSHjFZIjwE2oxmYAVwxAXRWTDEos8A+qr0HFp7d6fXmqlQY
MQh/i8fmPjUHFqR0TeCIbBkCufP6u/JOnb3zHmdp9LE00sY/hC5VNYeAgvmE8l/P
iZz30Z+FRpa0Y5LwAMqBiYUMe38W9reLD7qfMKB6bQZbMQY5BqmnOL0aFLT/618J
N5Ga71KoJLAEabQNYu2XP+b/29aAK3PWGqqasN24HrsgsAIluNYyR2MYV32g9E9P
9Hgl25PLcklBq8w1mBN8gFTcULk67aftpKwgyEEx2kDpYGdSxW4zw+lPikmtbmjh
Gruyipyu+CEp7H1pWrgEM6YKTBe82aa7gwh6im3AA42bHtnJCZEq2BXY1JD/oWrx
+n8pmw7uOh9s2onyiPA=
=5jct
-----END PGP SIGNATURE-----