|
|
|
|
|
by charcircuit
246 days ago
|
|
It shouldn't have happened in the first place. OpenSSH should control their exact dependencies and Debian shouldn't be meddling with them and swapping them out, loading random code into OpenSSH's process. >we can only trust open source software. There is no way to audit closed source software The ability to audit software is not sufficient, nor neccessary for it to be trustworthy. >systems of a closed source vendor was compromised, like Crowdstrike some weeks ago, we can’t audit anything You can't audit open source vendors either. |
|
Debian is the OS, and the OS vendor should decide and modify the components it uses as a foundation to create the OS as he desires. That's what I am choosing Debian for and not some other OS.
> You can't audit open source vendors either.
What defines open source, is that you can request the sources for audit and modification, so I think this statement is just untrue.