You are not logged in.
Pages: 1
I just noticed this article and made me wonder if a security mailing list would be obsolete with a rolling release?
http://distrowatch.com/weekly.php?issue … #editorial
Last edited by alleyoopster (2007-09-28 14:15:14)
Offline
Yeah, in fact they upgrade to the latest stable package (which contains security and bug fixes) every time one gets released, this lowers security risks. Is pretty much a nonsense having a security mailinglist this way cause you don't need to patch anything since pacman -Syu will always update to the latest stable package.
Offline
Unless the latest packages spend weeks in testing, you mean? There is always a good reason to keep an eye on security, simply having the latest packages/patches doesn't mean your system is secure. It means no known exploits in programs can be used by potential attackers, but it would be overly simplistic to reduce the concept of security to an up-to-date system.
Last edited by B (2007-09-28 09:08:20)
Got Leenucks? :: Arch: Power in simplicity :: Get Counted! Registered Linux User #392717 :: Blog thingy
Offline
A security mailing list can tell you that a security flaw has been found, when a fix is available, and even what that fix is. It's then up to you and your distro HOW the fixes are provided, i.e. patches, package updates, rolling update etc.
Notification does not presuppose whether you have or don't have rolling upgrades by itself.
It's no good having rolling upgrades if people don't know that a package has been upgraded for security reasons and they should seriously consider installing it. Security updates can have a role to play in that communication process.
I'm relatively new to Arch, if we don't use some kind of notification what do we use?
Russ
Offline
In my opinion having such a security list here in Arch will be just a waste of time for the Devs there are not many and they are always busy. So I believe we should not be that paranoid about security. Sure there is a 1 in a 100 chance you can be a target, but nothing a good stealthy firewall would not help you fix.
Offline
Hi,
on the "normal" arch-mailinglist there are some posts from JJDaNiMoTh. He post regularly/irregularly some security alarms. See this: http://archlinux.org/pipermail/arch/200 … 15114.html and this: http://archlinux.org/pipermail/arch/200 … 15072.html for example.
Daniel
Offline
Pages: 1