<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/19787/New_Security_Holes_Discovered</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2009, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Tue, 10 Nov 2009 10:35:24 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>Very Serious Discussion</title>
			<link>http://osnews.com/thread?315638</link>
			<guid isPermaLink="true">http://osnews.com/thread?315638</guid>
			<description>It's all made very clear for me now. I know which Distro is the best. Thanks to those guys (people - in case there are any cool chicks there) for making it easy on all of us.</description>
			<pubDate>Mon, 26 May 2008 19:02:00 GMT</pubDate>
			<author>donotreply@osnews.com (kjwaugh)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>witty</title>
			<link>http://osnews.com/thread?315659</link>
			<guid isPermaLink="true">http://osnews.com/thread?315659</guid>
			<description>Just the remedy after a busy working day... on a bank holiday <img src="/images/emo/sad.gif" alt=";)" /></description>
			<pubDate>Mon, 26 May 2008 20:16:00 GMT</pubDate>
			<author>donotreply@osnews.com (raver31)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>topic?</title>
			<link>http://osnews.com/thread?315672</link>
			<guid isPermaLink="true">http://osnews.com/thread?315672</guid>
			<description>Is it just me, or is the topic a little too vague and confusing? I mean, it's bad enough the teaser is almost always copy/pasted from the source, but can't there be a shred more of effort put in anymore?</description>
			<pubDate>Mon, 26 May 2008 22:02:00 GMT</pubDate>
			<author>donotreply@osnews.com (xushi)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: topic?</title>
			<link>http://osnews.com/thread?315676</link>
			<guid isPermaLink="true">http://osnews.com/thread?315676</guid>
			<description>Congratulations! You're the winner of this week's &quot;missing the point&quot; sweepstakes!</description>
			<pubDate>Mon, 26 May 2008 22:45:00 GMT</pubDate>
			<author>donotreply@osnews.com (David)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: topic?</title>
			<link>http://osnews.com/thread?315677</link>
			<guid isPermaLink="true">http://osnews.com/thread?315677</guid>
			<description>take a +1 from me... I can't give it normally as I have already posted <img src="/images/emo/sad.gif" alt=";)" /></description>
			<pubDate>Mon, 26 May 2008 23:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (raver31)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>openSUSE FTW</title>
			<link>http://osnews.com/thread?315682</link>
			<guid isPermaLink="true">http://osnews.com/thread?315682</guid>
			<description>It's gratifying to see that openSUSE managed to escape the list of glaring security problems.  Congrats to the dev teams, I believe their holistic approach to assessing vulnerabilities gives them a clear advantage over the distros listed in the article.<br />
<br />
FWIW, the bug with the decoder rings in Fedora was admittedly an issue with an earlier version of openSUSE, but it was very quickly identified and nixed with a security update.  It's remarkable to see that other distros fail, even in this day and age, to take preventative measures against well known attack vectors.  Don't even get me started on the root access vulnerability for slackware that was mentioned in the article, how has that not been addressed yet?<br />
<br />
Security is a mindset, above all else.<br />
<br />
;)</description>
			<pubDate>Tue, 27 May 2008 01:02:00 GMT</pubDate>
			<author>donotreply@osnews.com (elsewhere)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>I've realised I have too many tabs open...</title>
			<link>http://osnews.com/thread?315683</link>
			<guid isPermaLink="true">http://osnews.com/thread?315683</guid>
			<description>when I've found myself wondering where that xkcd comic come from, and where the security article was.</description>
			<pubDate>Tue, 27 May 2008 01:28:00 GMT</pubDate>
			<author>donotreply@osnews.com (wannabe geek)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>April Fool's?</title>
			<link>http://osnews.com/thread?315684</link>
			<guid isPermaLink="true">http://osnews.com/thread?315684</guid>
			<description>Sorry, I thought today was Memorial Day?<br />
<br />
For some reason this feels like a paid advertisement that was supposed to seem like a normal OSNews post... Didn't work for me, sorry. <img src="/images/emo/grin.gif" alt=";)" /></description>
			<pubDate>Tue, 27 May 2008 01:52:00 GMT</pubDate>
			<author>donotreply@osnews.com (patrick_)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>comic's inspiration</title>
			<link>http://osnews.com/thread?315693</link>
			<guid isPermaLink="true">http://osnews.com/thread?315693</guid>
			<description>I'm a little surprised not to see a link on OSNews to the incident that inspired this comic.  Maybe the editors knew it would turn into a flamefest.  Seriously though, it's somewhat of a major story.  I'm a Debian user myself, and I'm really horrified at the bug one of their developers introduced to their version of OpenSSL.  <br />
<br />
It's one of those things that makes one think about distros and their relationship to upstream, about whether one's distro choice is sound, about how easy it is to trust code, etc etc.  Seems like something that should be addressed on OSNews, even if it might be a crapstorm.  Apologies if I missed it somewhere..</description>
			<pubDate>Tue, 27 May 2008 04:26:00 GMT</pubDate>
			<author>donotreply@osnews.com (MamiyaOtaru)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: comic's inspiration</title>
			<link>http://osnews.com/thread?315717</link>
			<guid isPermaLink="true">http://osnews.com/thread?315717</guid>
			<description>I'm also a Debian user and am horrified as well.<br />
<br />
I'm considering switching to Arch linux due to their policy of not messing with the source that comes from the original maintainer.</description>
			<pubDate>Tue, 27 May 2008 09:28:00 GMT</pubDate>
			<author>donotreply@osnews.com (bloodandsoil)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: comic's inspiration</title>
			<link>http://osnews.com/thread?315723</link>
			<guid isPermaLink="true">http://osnews.com/thread?315723</guid>
			<description><div class="cquote">I'm considering switching to Arch linux due to their policy of not messing with the source that comes from the original maintainer. </div><br />
Arch seems to currently add three patches to their openssl package.<br />
<a href="http://repos.archlinux.org/viewvc.cgi/openssl/repos/core-i686/" rel="nofollow">http://repos.archlinux.org/viewvc.cgi/openssl/repos/core-i686/</a> <br />
<br />
Some Arch packages, like firefox, have more patches.<br />
<a href="http://repos.archlinux.org/viewvc.cgi/firefox/repos/extra-i686/" rel="nofollow">http://repos.archlinux.org/viewvc.cgi/firefox/repos/extra-i686/</a></description>
			<pubDate>Tue, 27 May 2008 10:59:00 GMT</pubDate>
			<author>donotreply@osnews.com (da_Chicken)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: openSUSE FTW</title>
			<link>http://osnews.com/thread?315815</link>
			<guid isPermaLink="true">http://osnews.com/thread?315815</guid>
			<description><div class="cquote">Don't even get me started on the root access vulnerability for slackware that was mentioned in the article, how has that not been addressed yet?<br />
<br />
Security is a mindset, above all else.<br />
<br />
;) </div><br />
<br />
Well, if your running Slackware 12.0, then yes, your most likely vulnerable, but it has been addressed with the release of 12.1, unless there is an issue with openssl-0.9.8g itself.</description>
			<pubDate>Tue, 27 May 2008 18:36:00 GMT</pubDate>
			<author>donotreply@osnews.com (Siamhie)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: topic?</title>
			<link>http://osnews.com/thread?315874</link>
			<guid isPermaLink="true">http://osnews.com/thread?315874</guid>
			<description>Did it for you, and you got a +1 too !</description>
			<pubDate>Wed, 28 May 2008 01:17:00 GMT</pubDate>
			<author>donotreply@osnews.com (holywood)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
