RE: [Full-Disclosure] Moox firefox/thunderbird builds. Anyone looked at these yet?

From: Stuart Fox (DSL AK) (StuartF_at_datacom.co.nz)
Date: 11/11/04

  • Next message: Mandrake Linux Security Team: "[Full-Disclosure] MDKSA-2004:129 - Updated ez-ipupdate packages fix format string vulnerability"
    To: "Eric Paynter" <eric@arcticbears.com>, <full-disclosure@lists.netsys.com>
    Date: Thu, 11 Nov 2004 13:10:48 +1300
    
    

    >
    > I wonder why somebody would branch just to do performance
    > improvements?

    Because people want their browser to perform quickly?

    > Why not just work with the mozilla team and apply the changes
    > to the source tree? It's not like he's adding features and
    > the team didn't want them because they would add to bloat.
    > Makes me wonder if there is a hidden agenda is these custom builds...

    Because it doesn't look like he's actually making changes to the code,
    he's just compiling with specific support for certain processor features
    which aren't included in a general (unoptimised) build. Basically,
    Mozilla distribute a vanilla build that will run on everything, and this
    guy is compiling with support for specific processor optimisations that
    won't run on processors that don't support those features.

    >
    > Or maybe I'm just a super paranoid security professional.

    You probably are being a little paranoid, although I prefer to run the
    binaries as distributed by the supplier (I of course trust that they
    haven't included backdoors, and they have compiled it sensibly. For me,
    any open source application I run is essentially closed source
    anyway...).

    If you were being super paranoid, you could generate your own optimised
    build - once you'd read through all the source code looking for security
    holes of course...

    Stu

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Mandrake Linux Security Team: "[Full-Disclosure] MDKSA-2004:129 - Updated ez-ipupdate packages fix format string vulnerability"

    Relevant Pages

    • Re: supporting older JVMs
      ... features and compiling it as "-source 1.4" works fine. ... Best compile against that older JVM when you need to support it or you're ... still for our externally visible APIs, many of our best customers require it ...
      (comp.lang.java.help)
    • SourceForge.net Sitewide update June 23rd, 2004 (fwd)
      ... Puzzle ITC provides software development services based on Open Source ... support of SourceForge.net. ... recent rolled out several other new features, ... lists. ...
      (comp.os.linux.announce)
    • Re: Distributions vs kernel development
      ... > That's interesting - what I find dissapointing about the Linux From Scratch ... And how many users are you trying to support? ... > distribution than an installation from source. ... > on-going use of a system, I think compiling from source is better overall. ...
      (Linux-Kernel)
    • mm/slub.c warnings
      ... I get these warnings when compiling mm/slub.c in linux-2.6.git: ... # Linux kernel version: 2.6.24 ... # Device Drivers ... # PCI IDE chipsets support ...
      (Linux-Kernel)
    • Re: B-Tree Index Usage
      ... Your support provider must apply pressure. ... in a public forum thanking you for your report. ... that many people don't use many of the "newer" features in D3 ... cared about "features" and pro-active vendors have moved on to vendors ...
      (comp.databases.pick)