Re: FreeBSD Security Advisory FreeBSD-SA-02:21.tcpip

From: Karsten W. Rohrbach (karsten@rohrbach.de)
Date: 04/20/02


Date: Sat, 20 Apr 2002 02:26:30 +0200
From: "Karsten W. Rohrbach" <karsten@rohrbach.de>
To: Brett Glass <brett@lariat.org>


Brett Glass(brett@lariat.org)@2002.04.19 16:12:33 +0000:
> At 04:07 PM 4/19/2002, Doug Barton wrote:
>
> >I long ago forgot what it was like to be a new
> >FreeBSD user,
>
> This is part of the problem here. We should care a lot about
> newcomers' experience, and respect the fact that no matter
> how bright they are they cannot learn everything at once.
> Expecting a new user to master CVSup is unreasonable.

brett,
i'm sorry, but reading this thread made me think about the days when i
started using freebsd and set up my first server. after being left alone
at a root user prompt "# " i learned how to configure the stuff in /etc,
that docs are in /usr/share/doc, how to install packages, and then how
to cvsup (for building upt to date versions out of the ports tree).

in my personal opinion, i find the RPM or binary-only distribution
mechanism very dangerous for users, because it is mainly the microsoft
approach to hide software complexity behind an interface the user has to
trust. i personally do not trust binary package systems (although i am
forced to use them sometimes), nor do i blindly trust the ports tree.
yes, i mean i _read_ the make files and view the output of the make
process before installing a port the first time on one box. then i make
a package out of it. that's all personal preference, yes.

IMVHO, what would be a good thing[tm] for the source dist (/usr/src) is
a Changelog file, containing the history of major fixes/enhancements to
the currently installed sources. it would be very easy to write a little
wrapper that saves /usr/src/Changelog (or maybe even a whole hierarchy
of subsystem Changelogs) to a backup and then diffs out the changes
after the update completed. this gives at least some overview about what
has changed and where to look for potential breakage.
it would be very good, if some of the committers could comment on that.

regards,
/k

-- 
> It's not that perl programmers are idiots, it's that the language rewards
> idiotic behavior in a way that no other language or tool has ever done. 
> --Erik Naggum 
KR433/KR11-RIPE -- WebMonster Community Founder -- nGENn GmbH Senior Techie
http://www.webmonster.de/ -- ftp://ftp.webmonster.de/ -- http://www.ngenn.net/
GnuPG 0x2964BF46 2001-03-15 42F9 9FFF 50D4 2F38 DBEE  DF22 3340 4F4E 2964 BF46
My mail is GnuPG signed -- Unsigned ones are bogus -- http://www.gnupg.org/
Please do not remove my address from To: and Cc: fields in mailing lists. 10x

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: gettext/GPLv4 virus infects FreeBSD
    ... remember that the FreeBSD ports tree is not branched. ... You might find it easier jpd, by cutting down the time spent calling ... We don't play the blame game here. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: FreeBSD or OpenBSD
    ... > Should I make the switch from FreeBSD to OpenBSD for my servers? ... OpenBSD has proactively rabid security. ... negates the advantage of FreeBSD's larger ports tree for a server. ... Source upgrades (OpenBSD offers no official support for the ...
    (freebsd-questions)
  • Xorg 7.3 Works Fine Now - But .. A Few More Questions
    ... no longer being in he ports tree. ... Current Operating System: FreeBSD ozzie.tundraware.com 6.2-STABLE FreeBSD ... Module "ramdac" already built-in ...
    (freebsd-questions)
  • Re: Update Utility
    ... |>Subject: Re: Update utility ... |>> Is there any utility in FreeBSD 4.9 to check for possible updates/bug ... |>other than if you find a security advisory, you have to have the src ... |>since most daemons/applications are from ports, keeping your ports tree ...
    (freebsd-questions)
  • How do YOU stay up to date?
    ... I'm finally getting my arms around FreeBSD and the updating processes ... I now understand how to use cvsup to keep my src and ports tree current. ... I know how to use pkg_add -r to install new sotware, ...
    (freebsd-questions)