LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

Impact of the Debian OpenSSL vulnerability

Impact of the Debian OpenSSL vulnerability

Posted May 18, 2008 16:11 UTC (Sun) by dvdeug (subscriber, #10998)
In reply to: Impact of the Debian OpenSSL vulnerability by Miravlix
Parent article: Impact of the Debian OpenSSL vulnerability

Virtually all of the code that most people run comes from the distribution. If no one is
looking at the distribution-local patches, then it is a failure of the many eyes concept. If
the distributions aren't sending their patches upstream, or the upstream is actively hostile
to the distributions, then it's a failure of the many eyes concept. Not that this would have
got noticed in a proprietary system until many systems got hacked, but that's no excuse.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds