Re: deploy openssl patch

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: misc <misc@...>
Date: Thursday, November 1, 2007 - 7:02 am

Markus Wernig wrote:

And by making security updates more difficult, you think you have
improved security, right?

As you have demonstrated, you have not. If an attacker can use your
system's compile tools, they can also install the compile tools. But
it DOES take you longer to do all you can to keep them out in the first
place.

> I would thus need to pre-compile libssl on a 4.2 buildhost

yes, just make a release, and install that.

Or, install the compilation tools where you need them and be done with
it.

Nick.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
deploy openssl patch, Markus Wernig, (Thu Nov 1, 6:33 am)
Re: deploy openssl patch, Clint Pachl, (Thu Nov 1, 5:25 pm)
Re: : deploy openssl patch, Raimo Niskanen, (Fri Nov 2, 8:23 am)
Re: : deploy openssl patch, Ray Percival, (Sat Nov 3, 1:30 pm)
Re: : deploy openssl patch, Clint Pachl, (Fri Nov 2, 3:43 pm)
Re: deploy openssl patch, Maurice Janssen, (Thu Nov 1, 7:55 am)
Re: deploy openssl patch, Nick Holland, (Thu Nov 1, 7:02 am)
Re: deploy openssl patch, z0mbix, (Thu Nov 1, 6:40 am)