Gentoo Archives: gentoo-user

From: Miroslav Rovis <miro.rovis@××××××××××××××.hr>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Reading the (SSL) traffic with Pale Moon
Date: Tue, 20 Dec 2016 15:10:17
Message-Id: 20161220151029.GC8158@g0n.xdwgrp
In Reply to: Re: [gentoo-user] Reading the (SSL) traffic with Pale Moon by Walter Dnes
1 Thanks! I'll be studying the links that you gave!
2 (I just replied to your other, later mail, first, in this thread, both
3 the mails, and I marked both important in my Mutt.)
4
5 On 161219-18:33-0500, Walter Dnes wrote:
6 > On Mon, Dec 19, 2016 at 06:43:53PM +0100, Miroslav Rovis wrote
7 >
8 > > And whether the NSS that Pale Moon uses is fine, maybe some of the devs
9 > > can tell us, I apologize for for having made too hasty and very probably
10 > > wrong conclusion in regard...
11 >
12 > See the 2nd post in https://forum.palemoon.org/viewtopic.php?t=8971
13 >
14 > Moonchild (the lead developer)
15 > > The moment I am given access to the MozSec bugs after each 6-week
16 > > release, I perform a full security audit on the bugs and code
17 > > for applicability. If a vulnerability exists in Pale Moon that is
18 > > addressed by these bugs, it is patched in the next release, with
19 > > chemspill releases for urgent security issues pushed out asap in a
20 > > point release.
21 >
22 > There is some informal slang here that you may not understand...
23 > * "chemspill" ==> an emergency similar in nature to a hazardous chemical
24 > spill, requiring immediate response
25 > * "asap" ==> an acronym for "As Soon As Possible"
26 >
27 > 3rd post in same thread
28 > Matt Tobin (developer)
29 > > One thing to keep in mind is that just because there is a vulnerability
30 > > in a codebase doesn't mean that there always was a vulnerability. As
31 > > most know, Mozilla has been rewriting code (refactoring) at a rabid
32 > > pace and has actually introduced more security flaws just by
33 > > refactoring and rewriting the code badly than were previously there
34 > > in the older incarnation of a chunk of code.
35 >
36 > Short summary...
37 > * Pale Moon is an independant fork
38 > * Pale Moon started out with a snapshot of Firefox code
39 > * Pale Moon has made its own set of changes
40 > * Mozilla (Firefox) has made a different set of changes
41 > * the two browsers' source code is different enough that a problem that
42 > affects Firefox may not affect Pale Moon; see...
43 > https://forum.palemoon.org/viewtopic.php?f=1&t=13984
44 > * if there are real problems, there are point releases. That's one
45 > reason why Pale Moon 27.0.1 and 27.0.2 and 27.0.3 have been released.
46 > E.g. see "Security-related and crash fixes:" in
47 > https://forum.palemoon.org/viewtopic.php?f=1&t=14223
48 >
49 > --
50 > Walter Dnes <waltdnes@××××××××.org>
51 > I don't run "desktop environments"; I run useful applications
52 >
53
54 Thanks!
55
56 --
57 Miroslav Rovis
58 Zagreb, Croatia
59 http://www.CroatiaFidelis.hr

Attachments

File name MIME type
signature.asc application/pgp-signature