Latexluv opened this issue on Oct 12, 2014 ยท 96 posts
shvrdavid posted Mon, 15 December 2014 at 8:34 PM
@pumeco
You talk about Debian users not having to worry about anything, but you must not have been a Debian base user between 2006 and 2009.
If you were, chances a better than good that your system was compromised and data mined.
There was a code change on it early in 2006, that introduced a huge security issue.
I know, I know, lots of people look at the code and it is all good.
Accept that for 2+ years and multiple updates (in 3 thru 4), no one writing Debian updates noticed that every Debian install had a serious security issue in OpenSSL.
Anyone that knew it was there was in your system so fast it wasn't funny.
The fix for it was drastic, and far more than just that had to be changed.
So much was changed, that there could be another issue in it that no one has discovered on the side that fixes it.
Did I mention that it still is not fixed???? Oh, just did...........
You always mention how safe and secure Debian is and it has had severe security issues in the past, and still has some.
To err is human, to really foul up requires a computer..... The errors continue to plague OpenSSL....
Here is the current list of OpenSSL issues in the very OS you are running. Some are fixed, others are not. Which means you are not as secure as you think you are.
https://packages.qa.debian.org/o/openssl.html
and
https://security-tracker.debian.org/tracker/source-package/openssl
And this is just the issues with OpenSSL....
Some things are easy to explain, other things are not........ <- Store -> <-Freebies->