1 |
Thanks! I'll be studying the links that you gave! |
2 |
(I just replied to your other, later mail, first, in this thread, both |
3 |
the mails, and I marked both important in my Mutt.) |
4 |
|
5 |
On 161219-18:33-0500, Walter Dnes wrote: |
6 |
> On Mon, Dec 19, 2016 at 06:43:53PM +0100, Miroslav Rovis wrote |
7 |
> |
8 |
> > And whether the NSS that Pale Moon uses is fine, maybe some of the devs |
9 |
> > can tell us, I apologize for for having made too hasty and very probably |
10 |
> > wrong conclusion in regard... |
11 |
> |
12 |
> See the 2nd post in https://forum.palemoon.org/viewtopic.php?t=8971 |
13 |
> |
14 |
> Moonchild (the lead developer) |
15 |
> > The moment I am given access to the MozSec bugs after each 6-week |
16 |
> > release, I perform a full security audit on the bugs and code |
17 |
> > for applicability. If a vulnerability exists in Pale Moon that is |
18 |
> > addressed by these bugs, it is patched in the next release, with |
19 |
> > chemspill releases for urgent security issues pushed out asap in a |
20 |
> > point release. |
21 |
> |
22 |
> There is some informal slang here that you may not understand... |
23 |
> * "chemspill" ==> an emergency similar in nature to a hazardous chemical |
24 |
> spill, requiring immediate response |
25 |
> * "asap" ==> an acronym for "As Soon As Possible" |
26 |
> |
27 |
> 3rd post in same thread |
28 |
> Matt Tobin (developer) |
29 |
> > One thing to keep in mind is that just because there is a vulnerability |
30 |
> > in a codebase doesn't mean that there always was a vulnerability. As |
31 |
> > most know, Mozilla has been rewriting code (refactoring) at a rabid |
32 |
> > pace and has actually introduced more security flaws just by |
33 |
> > refactoring and rewriting the code badly than were previously there |
34 |
> > in the older incarnation of a chunk of code. |
35 |
> |
36 |
> Short summary... |
37 |
> * Pale Moon is an independant fork |
38 |
> * Pale Moon started out with a snapshot of Firefox code |
39 |
> * Pale Moon has made its own set of changes |
40 |
> * Mozilla (Firefox) has made a different set of changes |
41 |
> * the two browsers' source code is different enough that a problem that |
42 |
> affects Firefox may not affect Pale Moon; see... |
43 |
> https://forum.palemoon.org/viewtopic.php?f=1&t=13984 |
44 |
> * if there are real problems, there are point releases. That's one |
45 |
> reason why Pale Moon 27.0.1 and 27.0.2 and 27.0.3 have been released. |
46 |
> E.g. see "Security-related and crash fixes:" in |
47 |
> https://forum.palemoon.org/viewtopic.php?f=1&t=14223 |
48 |
> |
49 |
> -- |
50 |
> Walter Dnes <waltdnes@××××××××.org> |
51 |
> I don't run "desktop environments"; I run useful applications |
52 |
> |
53 |
|
54 |
Thanks! |
55 |
|
56 |
-- |
57 |
Miroslav Rovis |
58 |
Zagreb, Croatia |
59 |
http://www.CroatiaFidelis.hr |