TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Lessons from the Debian/OpenSSL Fiasco

14 pointsby luckystrikeabout 17 years ago

2 comments

tptacekabout 17 years ago
Provide as many tips and rules of thumb as you want. Sometimes, it's safe to modify code you don't understand. And then, those tips will help. But that all goes out the window when it comes to security code. If you don't understand security code, don't mess with it.
ComputerGuruabout 17 years ago
Excellent points here, especially the bits about the rationale behind patching major packages when maintainers should be taking the extra time to submit patches upstream instead.