Gentoo Archives: gentoo-dev

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] why is the security team running around p.masking packages
Date: Thu, 07 Jul 2016 06:52:59
Message-Id: 8438794.IGfOcozxup@andromeda
In Reply to: Re: [gentoo-dev] why is the security team running around p.masking packages by Andrew Savchenko
1 On Wednesday, July 06, 2016 11:13:55 PM Andrew Savchenko wrote:
2 > On Wed, 06 Jul 2016 20:23:46 +0900 Aaron Bauman wrote:
3 .....
4
5 > Please understand me correctly: I'm not blaming you or security
6 > team for this or that issue. But it looks like security team indeed
7 > needs to review some policies and approaches to suit needs of
8 > Gentoo users better in both of terms of security and usability, to
9 > find some reasonable compromise between them, which will satisfy
10 > most users. For these very issues it looks like canceling "removal
11 > in 30 days" clause from p.mask action will do the job.
12
13 +1 on this. Please don't simply tree-clean packages because of security
14 issues. Masking them with a reference to the security issues should be
15 sufficient.
16
17 Some applications can easily be used safely even with gaping security holes.
18 (A heavily firewalled box or air-gap comes to mind).
19
20 --
21 Joost

Attachments

File name MIME type
signature.asc application/pgp-signature