From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id E7E3F139085 for ; Tue, 20 Dec 2016 15:10:17 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 660D3E0E75; Tue, 20 Dec 2016 15:10:00 +0000 (UTC) Received: from alt1.smtp5.plusvps.com (alt1.smtp5.plusvps.com [89.201.164.167]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id DED55E0D70 for ; Tue, 20 Dec 2016 15:09:59 +0000 (UTC) Received: from lin16.mojsite.com ([178.218.164.164]) by smtp5.plusvps.com with esmtps (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.84) (envelope-from ) id 1cJM3A-000B5F-FQ for gentoo-user@lists.gentoo.org; Tue, 20 Dec 2016 16:09:56 +0100 Received: from 78-0-222-187.adsl.net.t-com.hr ([78.0.222.187]:52158 helo=g0n.localdomain) by lin16.mojsite.com with esmtpsa (TLSv1:DHE-RSA-AES256-SHA:256) (Exim 4.87) (envelope-from ) id 1cJM39-0006Fv-D3 for gentoo-user@lists.gentoo.org; Tue, 20 Dec 2016 16:09:55 +0100 Received: by g0n.localdomain (Postfix, from userid 1000) id 58BB56BC4; Tue, 20 Dec 2016 16:10:29 +0100 (CET) Date: Tue, 20 Dec 2016 16:10:29 +0100 From: Miroslav Rovis To: gentoo-user@lists.gentoo.org Subject: Re: [gentoo-user] Reading the (SSL) traffic with Pale Moon Message-ID: <20161220151029.GC8158@g0n.xdwgrp> References: <20161218015637.GC18283@waltdnes.org> <20161218055009.GA11155@g0n.xdwgrp> <20161218070441.GA19833@waltdnes.org> <20161218181616.GA13242@g0n.xdwgrp> <20161218184347.GB13242@g0n.xdwgrp> <20161218202933.GA23487@waltdnes.org> <20161219111643.GA31077@g0n.xdwgrp> <20161219171701.GE31077@g0n.xdwgrp> <20161219174353.GF31077@g0n.xdwgrp> <20161219233337.GA15948@waltdnes.org> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-user@lists.gentoo.org Reply-to: gentoo-user@lists.gentoo.org MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="bAmEntskrkuBymla" Content-Disposition: inline In-Reply-To: <20161219233337.GA15948@waltdnes.org> User-Agent: Mutt/1.7.2 (2016-11-26) X-PlusHosting-MailScanner: Not scanned: please contact your Internet E-Mail Service Provider for details, Found to be clean X-PlusHosting-MailScanner-SpamCheck: X-Spam-Status: No, No X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - lin16.mojsite.com X-AntiAbuse: Original Domain - lists.gentoo.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - croatiafidelis.hr X-Get-Message-Sender-Via: lin16.mojsite.com: authenticated_id: miro.rovis@croatiafidelis.hr X-Authenticated-Sender: lin16.mojsite.com: miro.rovis@croatiafidelis.hr X-PlusHosting-MailScanner-Information: Please contact the ISP for more information X-PlusHosting-MailScanner-ID: 1cJM3A-000B5F-FQ X-PlusHosting-MailScanner-From: miro.rovis@croatiafidelis.hr X-Archives-Salt: a7b5271f-6b4c-4a27-b270-99cf1882856c X-Archives-Hash: 77963e2ef2d285a7a26e192c493e83ac --bAmEntskrkuBymla Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Thanks! I'll be studying the links that you gave! (I just replied to your other, later mail, first, in this thread, both the mails, and I marked both important in my Mutt.) On 161219-18:33-0500, Walter Dnes wrote: > On Mon, Dec 19, 2016 at 06:43:53PM +0100, Miroslav Rovis wrote >=20 > > And whether the NSS that Pale Moon uses is fine, maybe some of the devs > > can tell us, I apologize for for having made too hasty and very probably > > wrong conclusion in regard... >=20 > See the 2nd post in https://forum.palemoon.org/viewtopic.php?t=3D8971 >=20 > Moonchild (the lead developer) > > The moment I am given access to the MozSec bugs after each 6-week > > release, I perform a full security audit on the bugs and code > > for applicability. If a vulnerability exists in Pale Moon that is > > addressed by these bugs, it is patched in the next release, with > > chemspill releases for urgent security issues pushed out asap in a > > point release. >=20 > There is some informal slang here that you may not understand... > * "chemspill" =3D=3D> an emergency similar in nature to a hazardous chemi= cal > spill, requiring immediate response > * "asap" =3D=3D> an acronym for "As Soon As Possible" >=20 > 3rd post in same thread > Matt Tobin (developer) > > One thing to keep in mind is that just because there is a vulnerability > > in a codebase doesn't mean that there always was a vulnerability. As > > most know, Mozilla has been rewriting code (refactoring) at a rabid > > pace and has actually introduced more security flaws just by > > refactoring and rewriting the code badly than were previously there > > in the older incarnation of a chunk of code. >=20 > Short summary... > * Pale Moon is an independant fork > * Pale Moon started out with a snapshot of Firefox code > * Pale Moon has made its own set of changes > * Mozilla (Firefox) has made a different set of changes > * the two browsers' source code is different enough that a problem that > affects Firefox may not affect Pale Moon; see... > https://forum.palemoon.org/viewtopic.php?f=3D1&t=3D13984 > * if there are real problems, there are point releases. That's one > reason why Pale Moon 27.0.1 and 27.0.2 and 27.0.3 have been released. > E.g. see "Security-related and crash fixes:" in > https://forum.palemoon.org/viewtopic.php?f=3D1&t=3D14223 >=20 > --=20 > Walter Dnes > I don't run "desktop environments"; I run useful applications >=20 Thanks! --=20 Miroslav Rovis Zagreb, Croatia http://www.CroatiaFidelis.hr --bAmEntskrkuBymla Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJYWUnlAAoJEOqYhIhPuvCuHokQAI8oGc+R0xBXTWyyFXgKP5n5 niDJj5xqgnctnZiNbhPVhWjaDIdXKQa4VyaiJzoOdU1Ued7OvZUXy07lXxFAWUMh qRNq4k2tjNnukRwemKKVub81y+6N0h3hdyKrf4TRQEyfnmt61lSCWwGIwvzMs8Cg i3KSHW5+xeCW3XHO72zxp9H/PZvMuVLOivxunG+nst0R8oAC6t2qYi7T6tUVYwBQ Nw3d/CmVGEQxti3aWn9O3ucOc/mxj8EASbD7+o2E+XxRpyLMvb0O12teO3TBWBQM 5dqfpwaKQTKe1NMskQ+PhF0HBXdwD9Z2vkiHUUAIu9DBoEepHKpvmGPCvwRWlQzm Y7btId07bkztYzJsyRaWxfe7XG7UKF3yBOGQ94yZpUmMHwxqLOq3gp1wgYIPQ8CA 8EYKoZvRC6QEZmuaYpPMc2r3Y8/mBtl/DLAUOgE33N65+JMm/nbHZH1e8cMmAEwd UjzxQkyUeNvZlKYxj8j00dOFwwkmie1RspodE8RIAs/MpoAnf32mxRpUORqiLi/J 2gt9IT5wM2YXcTIoI2jH2Fq5nmgLuiKYARpXGM1iCPKJy7/8+peX8LMvFSM6oMd7 7eunHHpAvHEzxqPAxZSxbptzsdslWH+qqWAIwhiRfYmpKcWaBtzycVM8L4CfwnJY OvW51AUWCgyFp0SispoB =m770 -----END PGP SIGNATURE----- --bAmEntskrkuBymla--