Re: zip and unzip
Flareon Zulu <[email protected]> Thu, 19 Dec 2019 19:06:16 -0700
| Newsgroups | gmane.linux.lfs.general |
|---|---|
| Message-ID | <CAGPVyKs=E1jubeM=_D601spOm4_Vc9S4Br=uLhavmk3annjw=w@mail.gmail.com> |
On Thu, Dec 19, 2019 at 12:22 PM Aleksandar Kuktin <[email protected]> wrote: > Hi Laura and all! > > >On Mon, 16 Dec 2019 08:30:22 -0500 > >LM <[email protected]> wrote: > > > Was wondering what resources others use to look up security issues and > > fixes. I typically just check some of the main distributions (like > > Debian) and see what patches they've added to deal with security. > > I'm sure there are better ways to keep up with that type of > > information. Any recommendations? Thanks. > > A long time ago (2009-2013), I used to read security advisories > (emails) from the Croatian CERT (I was living in Croatia at the time). > They normally referenced CVE, and you almost always had a breadcrumb > trail to a patch you could apply to the code. I remember I would > cumulatively spend an hour or two each week patching my LFS. > > But sometime about the end of 2012, the main CVE database started to > get really silent and worthless. You would get an advisory, it would > only reference the CVE ID, but CVE would only tell you the ID is > reserved. It gave absolutely no indication what was going on. So you > literally knew you had *some* vulnerability on your system, but had no > practical way of fixing it. > > For a time I tried to fight the system, and would spend several hours > per week wrestling the patches from the Upstream/Internet/Void/Wherever > but it was just too much - I was under a vanishingly small actual real > world risk of having my system actually exploited and the effort simply > got too expensive for that risk (and keeping in mind other things I > could be doing). > > I'm still following several distro security advisory lists, still > regularly read the email and *still* tick off the emails for software I > have on my system. But I don't follow through on any of it - too little > time. > > Nowdays I rely on architectural security - different computers handle > different grades of sensitive material. *Really* serious stuff is more > or less airgapped, the rest is parceled out to several machines. > > I dream of a day when we would run hardware-software meshes that got > formally validated (so you *know* there are no security > vulnerabilities, or any bugs at all anywhere in the system) and then we > wouldn't NEED to patch things, other than for new features, three > times a lifetime. Maybe in 3000 years... > -- > http://lists.linuxfromscratch.org/listinfo/lfs-chat > FAQ: http://www.linuxfromscratch.org/blfs/faq.html > Unsubscribe: See the above information page > That is one hell of a pipe dream there. Good luck with that! Flareon Zulu -- http://lists.linuxfromscratch.org/listinfo/lfs-chat FAQ: http://www.linuxfromscratch.org/blfs/faq.html Unsubscribe: See the above information page