4 ms·
Mind explaining a bit more about the weaknesses of Debian in prod? I'm a Debian fanboy and from what I can gather people are still hung up over the SSH keys sec
by morrbo 6y ago
Mind explaining a bit more about the weaknesses of Debian in prod? I'm a Debian fanboy and from what I can gather people are still hung up over the SSH keys security fiasco (which was [and handled] extremely bad ofc) a long time ago, but am obviously wrong here so would love some enlightenment from someone in the know
- neilv 6y agoThe keys incident was a good example of one general weakness that I'd want to vet: how easy is it for an arbitrary one of the numerous Debian package maintainer to introduce a change (accidentally or intentionally) that compromises the system? Before that incident, I'd already had mixed feelings about Debian-specific changes to upstream, and one of those turned out to be a whopper. One thing that's reassuring: both of us thought immediately of the same incident, from years ago, so there's not like there's a stream of known defects discovered frequently, like in some other other areas of this general kind of system. Another thing that's reassuring about Debian is that some of their principles or policies align with security. For example, in the past I reported an instance in which upstream code of a package was effectively phoning-home to upstream unnecessarily, and Debian took it seriously, and fixed it. I like that the intent is there, so hopefully they'll catch many problems before I have to, and not introduce new problems on top of upstream.