Rate of bugs and rate of security holes are mostly uncorrelated
Posted Mar 7, 2006 5:24 UTC (Tue) by
mattdm (subscriber, #18)
In reply to:
Rate of bugs and rate of security holes are mostly uncorrelated by Ross
Parent article:
Coverity releases first defect survey results
I haven't seen a distribution yet which doesn't run the X server as root and have it listening on TCP port 6000 + display number.
Check out Fedora Core, then. Still runs as root (although possibly limited by SELinux), but doesn't listen on TCP by default.
Now it is certainly possible to disable the TCP X transport (using the -notcp option when starting the server), but I don't think it is "normal".
-nolisten tcp with X.org. Actually, I think this *is* the default in the upstream Gnome GDM, so....
(
Log in to post comments)