Re: zip and unzip

Flareon Zulu <[email protected]> Thu, 19 Dec 2019 19:06:16 -0700
Newsgroups gmane.linux.lfs.general
Message-ID <CAGPVyKs=E1jubeM=_D601spOm4_Vc9S4Br=uLhavmk3annjw=w@mail.gmail.com>
On Thu, Dec 19, 2019 at 12:22 PM Aleksandar Kuktin <[email protected]> wrote:

> Hi Laura and all!
>
> >On Mon, 16 Dec 2019 08:30:22 -0500
> >LM <[email protected]> wrote:
>
> > Was wondering what resources others use to look up security issues and
> > fixes.  I typically just check some of the main distributions (like
> > Debian) and see what patches they've added to deal with security.
> > I'm sure there are better ways to keep up with that type of
> > information.  Any recommendations?  Thanks.
>
> A long time ago (2009-2013), I used to read security advisories
> (emails) from the Croatian CERT (I was living in Croatia at the time).
> They normally referenced CVE, and you almost always had a breadcrumb
> trail to a patch you could apply to the code. I remember I would
> cumulatively spend an hour or two each week patching my LFS.
>
> But sometime about the end of 2012, the main CVE database started to
> get really silent and worthless. You would get an advisory, it would
> only reference the CVE ID, but CVE would only tell you the ID is
> reserved. It gave absolutely no indication what was going on. So you
> literally knew you had *some* vulnerability on your system, but had no
> practical way of fixing it.
>
> For a time I tried to fight the system, and would spend several hours
> per week wrestling the patches from the Upstream/Internet/Void/Wherever
> but it was just too much - I was under a vanishingly small actual real
> world risk of having my system actually exploited and the effort simply
> got too expensive for that risk (and keeping in mind other things I
> could be doing).
>
> I'm still following several distro security advisory lists, still
> regularly read the email and *still* tick off the emails for software I
> have on my system. But I don't follow through on any of it - too little
> time.
>
> Nowdays I rely on architectural security - different computers handle
> different grades of sensitive material. *Really* serious stuff is more
> or less airgapped, the rest is parceled out to several machines.
>
> I dream of a day when we would run hardware-software meshes that got
> formally validated (so you *know* there are no security
> vulnerabilities, or any bugs at all anywhere in the system) and then we
> wouldn't NEED to patch things, other than for new features, three
> times a lifetime. Maybe in 3000 years...
> --
> http://lists.linuxfromscratch.org/listinfo/lfs-chat
> FAQ: http://www.linuxfromscratch.org/blfs/faq.html
> Unsubscribe: See the above information page
>

That is one hell of a pipe dream there. Good luck with that!

Flareon Zulu

-- 
http://lists.linuxfromscratch.org/listinfo/lfs-chat
FAQ: http://www.linuxfromscratch.org/blfs/faq.html
Unsubscribe: See the above information page