Gentoo Archives: gentoo-security

From: JD Horelick <jdhore1@×××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] No GLSA since January?!?
Date: Fri, 26 Aug 2011 16:58:44
Message-Id: CAFhp8z6Nu8kRgcF3CB2K_nv0o+9BCFvVfiXZaqCVay=e+JbWEA@mail.gmail.com
In Reply to: Re: [gentoo-security] No GLSA since January?!? by Christoph Jasinski
1 On 26 August 2011 12:43, Christoph Jasinski <Krzysiek@×××.net> wrote:
2 > Dear Christian
3 >
4 > Everything is secure. No reason to write GLSAs or to panic. ;)
5 >
6 >
7 > Chris
8 >
9 > Am 26.08.2011 um 18:12 schrieb Christian Kauhaus:
10 >
11 >> Hi,
12 >>
13 >> I'm wondering that may favorite Linux distro hasn't had any security announcements since January. In my opinion this is really problematic. At our company we try to convince prospective customers to host their applications on our Gentoo servers. When asked about security incident handling, I have to say: "They state 'Security is a primary focus' on their website, but they don't inform their users." Not very convincing.
14 >>
15 >> So what is the roadblock that hinders GLSA creation? Is there any way to get the GLSAs into working order again?
16 >>
17 >> Regards
18 >>
19 >> Christian
20 >>
21 >> --
22 >> Dipl.-Inf. Christian Kauhaus <>< · kc@××××××.com · systems administration
23 >> gocept gmbh & co. kg · forsterstraße 29 · 06112 halle (saale) · germany
24 >> http://gocept.com · tel +49 345 1229889 11 · fax +49 345 1229889 1
25 >> Zope and Plone consulting and development
26 >>
27 >
28 >
29 >
30
31 I'm sorry, but I disagree with that. I've been an (unofficial) x86
32 Archtester for only 2 weeks or so and since then, i've seen more than
33 a few stabilizations needed to address security issues. Also, i've
34 noticed this same problem of not seeing many/any GLSA's in recent
35 history. As an example, in the past month, Debian has had 13 security
36 advisories. I personally doubt that we (Gentoo) don't have to worry
37 about ANY of those 13 advisories...

Replies

Subject Author
Re: [gentoo-security] No GLSA since January?!? "Daniel A. Avelino" <daavelino@×××××.com>