4 ms·
You had me until the anecdote. I understand the sentiment and intent of what’s being said, but as a security professional it just paints themselves, their appli
by kkirsche 4y ago
You had me until the anecdote. I understand the sentiment and intent of what’s being said, but as a security professional it just paints themselves, their applications, and their user base as targets. Knowing it’s a won’t fix means it’s also easier to sell exploits if not disclosing as it’s clear he doesn’t intend to upgrade to a maintained and supported version of Python, so it should work for longer than most exploits.
- 2rsf 4y agoOn a second look I see that they did moved to Python 3 with Calibre 5 on Sep 2020
- stevekemp 4y agoCalibre has a bad history with security already - for example https://lwn.net/Articles/464824/ https://lwn.net/Articles/464824/
- Gigachad 4y agoIf you use the program its plainly obvious this kind of opinion is well spread through it. Of course I deeply respect anyone who puts their work out for free as FOSS but the tool is not a shining example of good software.