Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] OpenVPN setup
Date: Mon, 18 Feb 2008 00:22:48
Message-Id: 49bf44f10802171622v7d20e46dic2d63dc674793f@mail.gmail.com
In Reply to: Re: [gentoo-user] OpenVPN setup by Albert Hopkins
1 > > Good points Albert. Is a daily 'emerge --sync && emerge -avDuN world'
2 > > generally enough as far as tracking security vulnerabilities?
3 > >
4 > > - Grant
5 >
6 > That's not really for me to say. But I can tell you that although the
7 > Gentoo developers take matters of security seriously, there is no
8 > full-time security tracker. Sometimes things don't get patched in
9 > portage until someone (else) creates a bug report. And even if that
10 > were not the case, there are 0-day exploits that have yet to be patched.
11 >
12 > So it really depends on how informed/paranoid you are about what you
13 > have accepting requests from the Internet.
14
15 While we're on the subject, what is the best way to stay on top of
16 security vulnerabilities for a group of services? Should I be
17 subscribed to their announcement mailing lists and make sure I'm
18 notified of new mail?
19
20 - Grant
21 --
22 gentoo-user@l.g.o mailing list