On Mon, Dec 19, 2016 at 06:43:53PM +0100, Miroslav Rovis wrote > And whether the NSS that Pale Moon uses is fine, maybe some of the devs > can tell us, I apologize for for having made too hasty and very probably > wrong conclusion in regard...
See the 2nd post in https://forum.palemoon.org/viewtopic.php?t=8971 Moonchild (the lead developer) > The moment I am given access to the MozSec bugs after each 6-week > release, I perform a full security audit on the bugs and code > for applicability. If a vulnerability exists in Pale Moon that is > addressed by these bugs, it is patched in the next release, with > chemspill releases for urgent security issues pushed out asap in a > point release. There is some informal slang here that you may not understand... * "chemspill" ==> an emergency similar in nature to a hazardous chemical spill, requiring immediate response * "asap" ==> an acronym for "As Soon As Possible" 3rd post in same thread Matt Tobin (developer) > One thing to keep in mind is that just because there is a vulnerability > in a codebase doesn't mean that there always was a vulnerability. As > most know, Mozilla has been rewriting code (refactoring) at a rabid > pace and has actually introduced more security flaws just by > refactoring and rewriting the code badly than were previously there > in the older incarnation of a chunk of code. Short summary... * Pale Moon is an independant fork * Pale Moon started out with a snapshot of Firefox code * Pale Moon has made its own set of changes * Mozilla (Firefox) has made a different set of changes * the two browsers' source code is different enough that a problem that affects Firefox may not affect Pale Moon; see... https://forum.palemoon.org/viewtopic.php?f=1&t=13984 * if there are real problems, there are point releases. That's one reason why Pale Moon 27.0.1 and 27.0.2 and 27.0.3 have been released. E.g. see "Security-related and crash fixes:" in https://forum.palemoon.org/viewtopic.php?f=1&t=14223 -- Walter Dnes <waltd...@waltdnes.org> I don't run "desktop environments"; I run useful applications