Mandriva, Mandrake, Lycoris In light of the many misunderstandings about Linux, software repositories and installation of packages, part one of this season's Mandriva Linux 2006 review includes an extensive background article about it. It explains why the nature of Free Software leads to a more userfriendly software installation setup for Linux distributions in general, as compared to proprietary systems such as the current desktop market leader. The process is illustrated with Mandriva Linux tools. This first part of the Mandriva Linux 2006 review also contains information on the installation and benchmark figures against previous Mandriva/Mandrake products, amongst other things.
by Temcat on Mon 7th Nov 2005 16:23 UTC in reply to "RE[3]: thumbs down"
No, but the fact is that they all come from the same developers

yes they do by definition, whether in a repository or not :-)

that they pass through lots of distro

...that also do not analyse most of the software for security that closely, because it is a really daunting task. That slightly increases coverage though, because different distro have different specialization. But no one of them does comprehensive analysis of all software.

that a lot of companies do security audits on lots of these software

on a limited set of software - mostly core one

and all that thanks to 2 things : GPL and source code available

which are a given whether or not an app is in a repository :-)

So in the end, it's still far better than any closed source app.

who spoke about closed source, buddy? :-)

I still never heard of any open source software with malware.

That IS the truth! And this is true not because of repos, but because of the availability of the source code.

The fact is that you could not do that with official repositories. Taking Mandriva, you would have to sneak in the new package, then manage to create a MD5 and SHA1 (think it's SHA1) for all the packages, which is already hard to defeat.

Hey, and why do I have to do that with repositories? I'll infect source that all repositories take. So that you could receive your malware properly signed :-)

WRONG ! Trusting ONE upstream you got the system from (Mandriva) is not comparable with trusting any random provider on the internet.

Dude, this provider IS the upstream! By definition. When a distro packages an app it hasn't thouroughly checked for security (which, as I said before, is the case for the most part of 17000 Mandriva packages), it means that they trust the author. And by installing this app from a repo, you implicitly trust him/her, too!

Oh, and why you are calling me a zealot is beyond me. Unless, of course, you define zealot as "having a different opinion on the general usefulness of repositories" :-)

