|
Message-ID: <20150402234357.GB9941@hunt>
Date: Thu, 2 Apr 2015 16:43:57 -0700
From: Seth Arnold <seth.arnold@...onical.com>
To: Sona Sarmadi <sona.sarmadi@...a.com>
Cc: oss-security@...ts.openwall.com, Solar Designer <solar@...nwall.com>
Subject: Re: membership request to the closed linux-distros
security mailing list
On Fri, Mar 20, 2015 at 02:00:29PM +0100, Sona Sarmadi wrote:
> On behalf of Enea Software AB, I would like to request membership to
> the closed linux-distros security mailing list.
Speaking strictly for myself, I'm still somewhat skeptical; the security
announce archives http://mail.lists.enea.com/pipermail/security-announce/
do show some security updates, but (guessing) 15% of the actual patch
links I tried to follow no longer exist.
Furthermore, the advisories all suggest downloading patches via http and
offer no mechanism to validate the patches before applying them. Consider
this recent advisory:
http://mail.lists.enea.com/pipermail/security-announce/20150326/000064.html
- there's no gpg signature on this advisory
- there's no cryptographic checksums in the advisory to authenticate
the patch even if the advisory were signed
- there's no ascii-armored signatures in the patches
- there's no detached signatures at
http://linux.enea.com/5.0-beta-m400/patches/
or at
http://linux.enea.com/4.0/patches/
If downloading patches and applying them by hand is really the
distribution model Enea has chosen, then it feels like the provenance
of updates is seriously lacking.
In my opinion, until some more of the security basics are covered,
joining linux-distros@ is premature.
Thanks
Download attachment "signature.asc" of type "application/pgp-signature" (474 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.