View Single Post
wicket's Avatar
Posts: 634 | Thanked: 3,266 times | Joined on May 2010 @ Colombia
#2
At the very least, I think we should upgrade to the latest OpenSSL 0.9.8. I think it's been suggested before to stick it in CSSU Testing but I don't know if anything came of it. As for POODLE mitigation in MicroB, disabling SSL3 via about:config ought to be enough and would be a lot less work than upgrading the browser engine (although a browser engine upgrade and newer OpenSSL would be very welcome).

A security audit is a very good idea. I've been meaning to run a vulnerability scanner such as OpenVAS or Nessus against Fremantle for some time now but I've never gotten around to doing it. It'd be great if someone would post the scan results here.
__________________
DebiaN900 - Native Debian on the N900. Deprecated in favour of Maemo Leste.

Maemo Leste for N950 and N9 (currently broken).
Devuan for N950 and N9.

Mobile devices with mainline Linux support - Help needed with documentation.

"Those who do not understand Unix are condemned to reinvent it, poorly." - Henry Spencer
 

The Following 8 Users Say Thank You to wicket For This Useful Post: