Update Blog #1 webpage from version 4.1.1.25 to 4.2.0.26

This commit is contained in:
inference 2023-09-02 20:15:45 +01:00
parent d0dedcb38e
commit 45d789eeb6
Signed by: inference
SSH Key Fingerprint: SHA256:FtEVfx1CmTKMy40VwZvF4k+3TC+QhCWy+EmPRg50Nnc

View File

@ -5,7 +5,7 @@
<!-- Copyright 2022 Jake Winters --> <!-- Copyright 2022 Jake Winters -->
<!-- SPDX-License-Identifier: BSD-3-Clause --> <!-- SPDX-License-Identifier: BSD-3-Clause -->
<!-- Version: 4.1.1.25 --> <!-- Version: 4.2.0.26 -->
<html> <html>
@ -34,28 +34,28 @@
<p class="update_date">Updated: 2022-11-14 (UTC+00:00)</p> <p class="update_date">Updated: 2022-11-14 (UTC+00:00)</p>
<!-- Table of contents --> <!-- Table of contents -->
<section id="toc"> <section id="toc">
<h2 id="toc"><a href="#toc" class="h2">Table of Contents<a/></h2> <h2 id="toc"><a href="#toc">Table of Contents<a/></h2>
<ul> <ul>
<li><a href="#issue0" class="body-link">Issue #0 - Against CVE Assignment</a></li> <li><a href="#issue0">Issue #0 - Against CVE Assignment</a></li>
<li><a href="#issue1" class="body-link">Issue #1 - CVEs Are Not Useful</a></li> <li><a href="#issue1">Issue #1 - CVEs Are Not Useful</a></li>
<li><a href="#issue2" class="body-link">Issue #2 - Security is a Circus</a></li> <li><a href="#issue2">Issue #2 - Security is a Circus</a></li>
<li><a href="#issue3" class="body-link">Issue #3 - Blaming the User</a></li> <li><a href="#issue3">Issue #3 - Blaming the User</a></li>
</ul> </ul>
</section> </section>
<p>Anyone who cares about security may want to switch from systemd as soon as possible; its lead <p>Anyone who cares about security may want to switch from systemd as soon as possible; its lead
developer doesn't care about your security at all.</p> developer doesn't care about your security at all.</p>
<section id="issue0"> <section id="issue0">
<h2 id="issue0"><a href="#issue0" class="h2">Issue #0 - Against CVE Assignment</a></h2> <h2 id="issue0"><a href="#issue0">Issue #0 - Against CVE Assignment</a></h2>
<br> <br>
<blockquote>"You don't assign CVEs to every single random bugfix we do, do you?"</blockquote> <blockquote>"You don't assign CVEs to every single random bugfix we do, do you?"</blockquote>
<p>- Lennart Poettering, systemd lead developer</p> <p>- Lennart Poettering, systemd lead developer</p>
<p>My thoughts:<br> <p>My thoughts:<br>
Yes, if they're security-related.</p> Yes, if they're security-related.</p>
<p>Source:<br> <p>Source:<br>
<a href="https://github.com/systemd/systemd/pull/5998#issuecomment-303782334" class="body-link">systemd GitHub Issue 5998</a></p> <a href="https://github.com/systemd/systemd/pull/5998#issuecomment-303782334">systemd GitHub Issue 5998</a></p>
</section> </section>
<section id="issue1"> <section id="issue1">
<h2 id="issue1"><a href="#issue1" class="h2">Issue #1 - CVEs Are Not Useful</a></h2> <h2 id="issue1"><a href="#issue1">Issue #1 - CVEs Are Not Useful</a></h2>
<blockquote>"Humpf, I am not convinced this is the right way to announce this. We never did that, and half the <blockquote>"Humpf, I am not convinced this is the right way to announce this. We never did that, and half the
CVEs aren't useful anyway, hence I am not sure we should start with that now, because it is either CVEs aren't useful anyway, hence I am not sure we should start with that now, because it is either
inherently incomplete or blesses the nonsensical part of the CVE circus which we really shouldn't inherently incomplete or blesses the nonsensical part of the CVE circus which we really shouldn't
@ -66,18 +66,18 @@
it *is* the correct way to announce it. It seems as if over 95 security-concious people think the it *is* the correct way to announce it. It seems as if over 95 security-concious people think the
same.</p> same.</p>
<p>Source:<br> <p>Source:<br>
<a href="https://github.com/systemd/systemd/pull/6225#issuecomment-311739869" class="body-link">systemd GitHub Issue 6225</a></p> <a href="https://github.com/systemd/systemd/pull/6225#issuecomment-311739869">systemd GitHub Issue 6225</a></p>
</section> </section>
<section id="issue2"> <section id="issue2">
<h2 id="issue2"><a href="#issue2" class="h2">Issue #2 - Security is a Circus</a></h2> <h2 id="issue2"><a href="#issue2">Issue #2 - Security is a Circus</a></h2>
<blockquote>"I am not sure I buy enough into the security circus to do that though for any minor <blockquote>"I am not sure I buy enough into the security circus to do that though for any minor
issue..."</blockquote> issue..."</blockquote>
<p>- Lennart Poettering, systemd lead developer</p> <p>- Lennart Poettering, systemd lead developer</p>
<p>Source:<br> <p>Source:<br>
<a href="https://github.com/systemd/systemd/issues/5144#issuecomment-276740654" class="body-link">systemd GitHub Issue 5144</a></p> <a href="https://github.com/systemd/systemd/issues/5144#issuecomment-276740654">systemd GitHub Issue 5144</a></p>
</section> </section>
<section id="issue3"> <section id="issue3">
<h2 id="issue3"><a href="#issue3" class="h2">Issue #3 - Blaming the User</a></h2> <h2 id="issue3"><a href="#issue3">Issue #3 - Blaming the User</a></h2>
<blockquote>"Yes, as you found out "0day" is not a valid username. I wonder which tool permitted you to create <blockquote>"Yes, as you found out "0day" is not a valid username. I wonder which tool permitted you to create
it in the first place. Note that not permitting numeric first characters is done on purpose: to it in the first place. Note that not permitting numeric first characters is done on purpose: to
avoid ambiguities between numeric UID and textual user names. avoid ambiguities between numeric UID and textual user names.
@ -93,7 +93,7 @@
systemd was the thing that allowed root access just because a username started with a number, then systemd was the thing that allowed root access just because a username started with a number, then
Poettering blamed the user.</p> Poettering blamed the user.</p>
<p>Source:<br> <p>Source:<br>
<a href="https://github.com/systemd/systemd/issues/6237#issuecomment-311900864" class="body-link">systemd GitHub Issue 6237</a></p> <a href="https://github.com/systemd/systemd/issues/6237#issuecomment-311900864">systemd GitHub Issue 6237</a></p>
</section> </section>
</body> </body>
</html> </html>