Re: replacing misleading debian.org/security claims

2022-01-21 Thread Pierre-Elliott Bécue
max wrote on 20/01/2022 at 22:51:24+0100: > January 18, 2022 11:28:48 PM CET "Pierre-Elliott Bécue" > wrote: > >> if you keep being pushy, ask that you are temporarily prevented to >> mail debian lists > > You didn't actually reply to my question addressed to you. That's true. The reason is

Re: replacing misleading debian.org/security claims

2022-01-20 Thread RP
I On 1/20/22 13:51, max wrote: January 18, 2022 11:28:48 PM CET "Pierre-Elliott Bécue" wrote: if you keep being pushy, ask that you are temporarily prevented to mail debian lists You didn't actually reply to my question addressed to you. All you did was publicly threaten me (and thus anyon

Re: replacing misleading debian.org/security claims

2022-01-20 Thread max
January 18, 2022 11:28:48 PM CET "Pierre-Elliott Bécue" wrote: > if you keep being pushy, ask that you are temporarily prevented to mail > debian lists You didn't actually reply to my question addressed to you. All you did was publicly threaten me (and thus anyone else who might be interested

Re: replacing misleading debian.org/security claims

2022-01-18 Thread Pierre-Elliott Bécue
max wrote on 18/01/2022 at 05:46:10+0100: > January 14, 2022 11:44:39 PM CET "Pierre-Elliott Bécue" > wrote: > >> Maybe at some time you could just stop keeping on insisting on that >> matter? > > I thought this was just an oversight, but since this is intentional, > it isn't. How can you poss

Re: replacing misleading debian.org/security claims

2022-01-17 Thread max
January 14, 2022 11:44:39 PM CET "Pierre-Elliott Bécue" wrote: > Maybe at some time you could just stop keeping on insisting on that matter? I thought this was just an oversight, but since this is intentional, it isn't. How can you possibly justify and continue such a flagrant misrepresentation

Re: replacing misleading debian.org/security claims

2022-01-14 Thread Robert Ricardo Ikaka
https://chng.it/jJvMChbdsJ сб, 15 янв. 2022 г., 01:45 Pierre-Elliott Bécue : > > max wrote on 14/01/2022 at 00:38:44+0100: > > > January 10, 2022 6:31:37 AM CET Salvatore Bonaccorso > wrote: > > > >> We are going to stop anyway at some point displaying the NVD severity, > for context see #9921

Re: replacing misleading debian.org/security claims

2022-01-14 Thread Pierre-Elliott Bécue
max wrote on 14/01/2022 at 00:38:44+0100: > January 10, 2022 6:31:37 AM CET Salvatore Bonaccorso > wrote: > >> We are going to stop anyway at some point displaying the NVD severity, for >> context see #992115. > > As I see it, Debian should be free to display or not display NVD > ratings, b

Re: replacing misleading debian.org/security claims

2022-01-13 Thread max
January 10, 2022 6:31:37 AM CET Salvatore Bonaccorso wrote: > We are going to stop anyway at some point displaying the NVD severity, for > context see #992115. As I see it, Debian should be free to display or not display NVD ratings, but it shouldn't display the incorrect "medium" NVD ratings,

Re: replacing misleading debian.org/security claims

2022-01-09 Thread Salvatore Bonaccorso
Hi, On Wed, Jan 05, 2022 at 02:20:46PM +0800, Paul Wise wrote: > > (Side note: It seems that NVD tends to assign "medium" severity to > > vulnerabilities initially, but upgrades them to "high" or "critical" > > later. However, Debian keeps showing the initial severity rating) > > Please send a pa

Re: replacing misleading debian.org/security claims

2022-01-09 Thread max
(Added: CC: secur...@debian.org as requested. Please see the mailing list archive if you need context) January 5, 2022 7:20:46 AM CET Paul Wise wrote: > This isn't entirely factual either. How about this (added "largely"): """ Debian's security updates are largely created by volunteers work

Re: replacing misleading debian.org/security claims

2022-01-04 Thread Paul Wise
On Thu, 2021-12-30 at 11:04 -0500, Silas Cutler wrote: > I'd also like to see information on both how to submit > vulnerabilities as well as how to contribute to getting them fixed. These are addressed in the FAQ: https://www.debian.org/security/faq#discover https://www.debian.org/security/faq#h

Re: replacing misleading debian.org/security claims

2022-01-04 Thread Paul Wise
On Tue, 2021-12-28 at 19:46 +0100, max wrote: > Debian's security updates are created by volunteers working in their > spare time. Some packages may receive more attention than others. To > view the current list of known unfixed vulnerabilities see > https://security-tracker.debian.org/tracker/sta

Re: replacing misleading debian.org/security claims

2021-12-30 Thread Silas Cutler
Hi Max - (First time poster (?Maybe) / long time lurker). I think highlighting that Debian is supported by volunteers is important and providing up front a link to tracker is outstanding. The "we take security seriously" text is dated consistent with standard boiler-plate text. I'd also li