Linked by Eugenia Loli on Mon 7th Nov 2005 00:10 UTC, submitted by Rob Teng
Permalink for comment 57358
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
Linked by Thom Holwerda on 05/17/13 23:35 UTC, submitted by kragil
Linked by MOS6510 on 05/17/13 22:22 UTC
Linked by Thom Holwerda on 05/17/13 22:15 UTC, submitted by Tom
Linked by Thom Holwerda on 05/16/13 21:41 UTC
Linked by Thom Holwerda on 05/16/13 17:04 UTC
Linked by Thom Holwerda on 05/16/13 13:17 UTC
Linked by Thom Holwerda on 05/16/13 12:06 UTC
More News »
Sponsored Links



Member since:
2005-10-18
No, but the fact is that they all come from the same developers
yes they do by definition, whether in a repository or not :-)
that they pass through lots of distro
...that also do not analyse most of the software for security that closely, because it is a really daunting task. That slightly increases coverage though, because different distro have different specialization. But no one of them does comprehensive analysis of all software.
that a lot of companies do security audits on lots of these software
on a limited set of software - mostly core one
and all that thanks to 2 things : GPL and source code available
which are a given whether or not an app is in a repository :-)
So in the end, it's still far better than any closed source app.
who spoke about closed source, buddy? :-)
I still never heard of any open source software with malware.
That IS the truth! And this is true not because of repos, but because of the availability of the source code.
The fact is that you could not do that with official repositories. Taking Mandriva, you would have to sneak in the new package, then manage to create a MD5 and SHA1 (think it's SHA1) for all the packages, which is already hard to defeat.
Hey, and why do I have to do that with repositories? I'll infect source that all repositories take. So that you could receive your malware properly signed :-)
WRONG ! Trusting ONE upstream you got the system from (Mandriva) is not comparable with trusting any random provider on the internet.
Dude, this provider IS the upstream! By definition. When a distro packages an app it hasn't thouroughly checked for security (which, as I said before, is the case for the most part of 17000 Mandriva packages), it means that they trust the author. And by installing this app from a repo, you implicitly trust him/her, too!
Oh, and why you are calling me a zealot is beyond me. Unless, of course, you define zealot as "having a different opinion on the general usefulness of repositories" :-)