Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> With maintainers in the loop, there is at least one more person that can notice something is fishy

Also one more person who can inject malware or break something. How did that Debian keygen issue happen again? Oh right.



> How did that Debian keygen issue happen again?

The people on the openssl mailing list said it was fine. That's how it happened.


And yet the upstream developers themselves never incorporated the change, it was entirely because an unnecessary third party middle man made unnecessary changes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: