Re: zip and unzip
Aleksandar Kuktin <[email protected]> Thu, 19 Dec 2019 20:20:50 +0100
| Newsgroups | gmane.linux.lfs.general |
|---|---|
| Message-ID | <20191219202050.5d911d74@ikilid> |
Hi Laura and all! >On Mon, 16 Dec 2019 08:30:22 -0500 >LM <[email protected]> wrote: > Was wondering what resources others use to look up security issues and > fixes. I typically just check some of the main distributions (like > Debian) and see what patches they've added to deal with security. > I'm sure there are better ways to keep up with that type of > information. Any recommendations? Thanks. A long time ago (2009-2013), I used to read security advisories (emails) from the Croatian CERT (I was living in Croatia at the time). They normally referenced CVE, and you almost always had a breadcrumb trail to a patch you could apply to the code. I remember I would cumulatively spend an hour or two each week patching my LFS. But sometime about the end of 2012, the main CVE database started to get really silent and worthless. You would get an advisory, it would only reference the CVE ID, but CVE would only tell you the ID is reserved. It gave absolutely no indication what was going on. So you literally knew you had *some* vulnerability on your system, but had no practical way of fixing it. For a time I tried to fight the system, and would spend several hours per week wrestling the patches from the Upstream/Internet/Void/Wherever but it was just too much - I was under a vanishingly small actual real world risk of having my system actually exploited and the effort simply got too expensive for that risk (and keeping in mind other things I could be doing). I'm still following several distro security advisory lists, still regularly read the email and *still* tick off the emails for software I have on my system. But I don't follow through on any of it - too little time. Nowdays I rely on architectural security - different computers handle different grades of sensitive material. *Really* serious stuff is more or less airgapped, the rest is parceled out to several machines. I dream of a day when we would run hardware-software meshes that got formally validated (so you *know* there are no security vulnerabilities, or any bugs at all anywhere in the system) and then we wouldn't NEED to patch things, other than for new features, three times a lifetime. Maybe in 3000 years... -- http://lists.linuxfromscratch.org/listinfo/lfs-chat FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page
signature.asc
(application/pgp-signature, 836 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.15 (GNU/Linux) iQIbBAEBAgAGBQJd+82SAAoJEKa4cgqNx31/3l0P9jwEOl5ZUluPtG8WRWD+6Can FRZZMXZW+bocOgrY5wAqM6LTfCgPDaBlucTtshIlOrK+Ds9nUo0gwnDT/KQJM0YZ 9EUQm1fDXKkHtxY4CBhdHX7/Dk7xEXyxZv9AI3l+udLYpWhu6IMk3YRH/Fug8/Qv mSrSEj9u09DxNSbelAHORzAU/H6xV7Q5eP6Qt6XgSDlEVv5jFweflsk6DkRCuJU2 afwDj22xz2czam9SWovNKVJ0+NxV8drll21QUSaUySmz2YEnQAjPQ755hhl8UHCe T9SO9NTxqfWqELF0iWSHjFZIjwE2oxmYAVwxAXRWTDEos8A+qr0HFp7d6fXmqlQY MQh/i8fmPjUHFqR0TeCIbBkCufP6u/JOnb3zHmdp9LE00sY/hC5VNYeAgvmE8l/P iZz30Z+FRpa0Y5LwAMqBiYUMe38W9reLD7qfMKB6bQZbMQY5BqmnOL0aFLT/618J N5Ga71KoJLAEabQNYu2XP+b/29aAK3PWGqqasN24HrsgsAIluNYyR2MYV32g9E9P 9Hgl25PLcklBq8w1mBN8gFTcULk67aftpKwgyEEx2kDpYGdSxW4zw+lPikmtbmjh Gruyipyu+CEp7H1pWrgEM6YKTBe82aa7gwh6im3AA42bHtnJCZEq2BXY1JD/oWrx +n8pmw7uOh9s2onyiPA= =5jct -----END PGP SIGNATURE-----