Re: switching libcurl back to OpenSSL and providing the libcurl-minimal subpackage

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Apr 10, 2017 at 03:52:32PM +0200, Kai Engert wrote:
> In my opinion, a little bit of space saving shouldn't be a sufficient
> argument for removing existing security functionality.

Space saving is nice, but that's not the real issue. It's a given that
all security libraries will have critical and urgent vulnerabilities
sometime in the future. By reducing the number of libraries in use in
the base system, we reduce the surface area. This is particularly
important where we have cascading artifacts built on a base — if the
bottom changes, there's a lot of churn.

-- 
Matthew Miller
<mattdm@xxxxxxxxxxxxxxxxx>
Fedora Project Leader
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx




[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux