Re: Concerns about how the Security information is presented on Debian.org

2021-12-21 Thread Andrey Rahmatullin
On Wed, Dec 22, 2021 at 02:15:04AM +0100, Agata Erminia Pennisi wrote: > Dear Max, > I am a simple user. > Thank you for notifying the community of the unresolved Chromium > vulnerabilities. > You can use official channels to report vulnerabilities. Chromium being full of vulnerabilities is well-k

Re: Concerns about how the Security information is presented on Debian.org

2021-12-21 Thread Agata Erminia Pennisi
Dear Max, I am a simple user. Thank you for notifying the community of the unresolved Chromium vulnerabilities. You can use official channels to report vulnerabilities. Also, if you find these vulnerabilities "dangerous" and underrated, report them to the community as you did with Chronium. You mus

Re: Concerns about how the Security information is presented on Debian.org

2021-12-21 Thread Max WillB
One DD replied off-the-list, so I'll quote him without attribution: > I understand your concern, but practicality is better then theory. > > (...) we will get notification when vulnerabilities are exploited, and so we > get priority. It's not so theoretical: "Google is aware that an exploit fo

Re: Concerns about how the Security information is presented on Debian.org

2021-12-21 Thread Max WillB
Dear Diederik, New code fixes old bugs, but introduces new ones. Then Debian comes in and, at some point, applies a small portion of those fixes to old code. My problem is that debian.org/security is not telling you that. People read the page and get the mistaken impression that all of Debian's