Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror

Comment Re:OSS, only as good as the last developer? (Score 1) 670

But the point here is that the freedom that OSS gives you does require you to trust the whole distribution chain. In this case there was an added muppet who did something they shouldn't have thus rendering everything downstream insecure. OSS is great but it required great developers, given that it has take well over a year to get the advisory out it shows that the many eyes piece didn't work here, mainly because the eyes were looking at the original source not the botched packaging job.
This is actually the number one reason I use slackware. Every package gets built by one guy. And if anything, it's easy to trust one guy. And he happens to be the one with the most experience at making packages. Not only that, his philosophy is to provide pristine packages from its source as far as possible. No worries of changes to these packages except critical bug fixes, and these are usually the kind that go upstream anyway.

Frankly, I'm not surprised that this occurred in Debian. I have seen how they package before. Usually that have the original source and one giant make-package-debian-centric diff file that would be insanely hard to audit -- correct me if I'm wrong -- at least for anyone outside debian or did not build the package in the first place.
Businesses

Best Buy Accused of Overcharging 301

An anonymous reader writes "Connecticut's Attorney General Richard Blumenthal has accused Best Buy of overcharging its customers. His accusation is that customers see one price on Best Buy's website, in stores salespeople would show them a different internal site from a kiosk. Best Buy denies the charges. 'Previously, the company confirmed that store employees have access to an internal Web site that looks nearly identical to the public BestBuy.com site, but the company's policy is always to offer customers the lowest quoted price unless it's specifically identified as a deal available only to online shoppers. Jerry Farrell Jr., Connecticut's consumer protection commissioner, said the lawsuit should be a warning to companies to be more transparent in their business practices.'"

Slashdot Top Deals

The difficult we do today; the impossible takes a little longer.

Working...