3 ms·
So we would be more trustworthy if we left millions of users vulnerable to being silently compromised by malware? No, Apache and Exim wouldn't get removed, the
by mdeslaur 15y ago
So we would be more trustworthy if we left millions of users vulnerable to being silently compromised by malware?
No, Apache and Exim wouldn't get removed, the source is available so a fix can be issued.
- saurik 15y agoStrawman. Every other suggestion on this page is more reasonable than the one Ubuntu is choosing, whether it be replacing the package with one that is 90% functionally equivalent (openjdk) to printing giant warnings during the package upgrade process. The decision made by Ubuntu is so uncaring for its user community that this reads like comedy.
- buntoo 15y agoRemoving packages seems to be the way Linux distros handle this type of issue https://rhn.redhat.com/errata/RHSA-2011-0368.html https://rhn.redhat.com/errata/RHSA-2011-0368.html https://rhn.redhat.com/errata/RHSA-2008-1045.html https://rhn.redhat.com/errata/RHSA-2008-1045.html
- gldalmaso 15y agoI disagree. Many people leave windows in favor of Ubuntu for increased security against virus and malware. I agree that there could be more transparent feedback to the user who probably will never check to see what's being update and why, but I don't think this reads like comedy at all.
- nirvdrum 15y agoMaybe a balance and not remove it on servers? I have a pretty locked down environment and trust my ability to read advisories and take necessary precautions. It's weird to presume your users can't deal with that.