3 ms·
Please be cautious about recommending KDE's Dolphin. According to Hanno Böck in https://media.ccc.de/v/SHA2017-148-improving_security_with_fuzzing_and_sanitizer
by sd8dgf8ds8g8dsg 9y ago
Please be cautious about recommending KDE's Dolphin.
According to Hanno Böck in https://media.ccc.de/v/SHA2017-148-improving_security_with_fuzzing_and_sanitizers https://media.ccc.de/v/SHA2017-148-improving_security_with_f..., KDE are refusing to sandbox the thumbnail/preview code, which has proven to be riddled with easy-to-find bugs (using software fuzzing)
- jcelerier 9y agohow do we know there aren't similar bugs with MS explorer / Finder ?
- spost 9y agoWell, we don't, but would you rather use software known to have bugs or software not known to have bugs?
- jcelerier 9y agouh... software whose bugs are known and whose source is accessible of course ? it's not like finder does not have CVEs: https://www.cvedetails.com/vulnerability-list/vendor_id-49/product_id-156/cvssscoremin-2/cvssscoremax-2.99/Apple-Mac-Os-X.html https://www.cvedetails.com/vulnerability-list/vendor_id-49/p....