On Mon, Dec 19, 2016 at 06:43:53PM +0100, Miroslav Rovis wrote

> And whether the NSS that Pale Moon uses is fine, maybe some of the devs
> can tell us, I apologize for for having made too hasty and very probably
> wrong conclusion in regard...

  See the 2nd post in https://forum.palemoon.org/viewtopic.php?t=8971

Moonchild (the lead developer)
> The moment I am given access to the MozSec bugs after each 6-week
> release, I perform a full security audit on the bugs and code
> for applicability. If a vulnerability exists in Pale Moon that is
> addressed by these bugs, it is patched in the next release, with
> chemspill releases for urgent security issues pushed out asap in a
> point release.

  There is some informal slang here that you may not understand...
* "chemspill" ==> an emergency similar in nature to a hazardous chemical
   spill, requiring immediate response
* "asap" ==> an acronym for "As Soon As Possible"

  3rd post in same thread
Matt Tobin (developer)
> One thing to keep in mind is that just because there is a vulnerability
> in a codebase doesn't mean that there always was a vulnerability. As
> most know, Mozilla has been rewriting code (refactoring) at a rabid
> pace and has actually introduced more security flaws just by
> refactoring and rewriting the code badly than were previously there
> in the older incarnation of a chunk of code.

  Short summary...
* Pale Moon is an independant fork
* Pale Moon started out with a snapshot of Firefox code
* Pale Moon has made its own set of changes
* Mozilla (Firefox) has made a different set of changes
* the two browsers' source code is different enough that a problem that
  affects Firefox may not affect Pale Moon; see...
  https://forum.palemoon.org/viewtopic.php?f=1&t=13984
* if there are real problems, there are point releases.  That's one
  reason why Pale Moon 27.0.1 and 27.0.2 and 27.0.3 have been released.
  E.g. see "Security-related and crash fixes:" in
  https://forum.palemoon.org/viewtopic.php?f=1&t=14223

-- 
Walter Dnes <waltd...@waltdnes.org>
I don't run "desktop environments"; I run useful applications

Reply via email to