Thanks! I'll be studying the links that you gave! (I just replied to your other, later mail, first, in this thread, both the mails, and I marked both important in my Mutt.)
On 161219-18:33-0500, Walter Dnes wrote: > On Mon, Dec 19, 2016 at 06:43:53PM +0100, Miroslav Rovis wrote > > > And whether the NSS that Pale Moon uses is fine, maybe some of the devs > > can tell us, I apologize for for having made too hasty and very probably > > wrong conclusion in regard... > > See the 2nd post in https://forum.palemoon.org/viewtopic.php?t=8971 > > Moonchild (the lead developer) > > The moment I am given access to the MozSec bugs after each 6-week > > release, I perform a full security audit on the bugs and code > > for applicability. If a vulnerability exists in Pale Moon that is > > addressed by these bugs, it is patched in the next release, with > > chemspill releases for urgent security issues pushed out asap in a > > point release. > > There is some informal slang here that you may not understand... > * "chemspill" ==> an emergency similar in nature to a hazardous chemical > spill, requiring immediate response > * "asap" ==> an acronym for "As Soon As Possible" > > 3rd post in same thread > Matt Tobin (developer) > > One thing to keep in mind is that just because there is a vulnerability > > in a codebase doesn't mean that there always was a vulnerability. As > > most know, Mozilla has been rewriting code (refactoring) at a rabid > > pace and has actually introduced more security flaws just by > > refactoring and rewriting the code badly than were previously there > > in the older incarnation of a chunk of code. > > Short summary... > * Pale Moon is an independant fork > * Pale Moon started out with a snapshot of Firefox code > * Pale Moon has made its own set of changes > * Mozilla (Firefox) has made a different set of changes > * the two browsers' source code is different enough that a problem that > affects Firefox may not affect Pale Moon; see... > https://forum.palemoon.org/viewtopic.php?f=1&t=13984 > * if there are real problems, there are point releases. That's one > reason why Pale Moon 27.0.1 and 27.0.2 and 27.0.3 have been released. > E.g. see "Security-related and crash fixes:" in > https://forum.palemoon.org/viewtopic.php?f=1&t=14223 > > -- > Walter Dnes <waltd...@waltdnes.org> > I don't run "desktop environments"; I run useful applications > Thanks! -- Miroslav Rovis Zagreb, Croatia http://www.CroatiaFidelis.hr
signature.asc
Description: Digital signature