Re: ssl security desaster (was: Re: SSH keys: DSA vs RSA)

On Thu May 15 2008 10:34:01 Peter Samuelson wrote:
> Who is this "we"?  Whose serious efforts?  Who is investigating?  Most
> importantly, should we assume that, as in the past, you, Mike Bird,
> intend to do nothing but talk?

Debian is still one of the world's best distros and I hope it
continues as such.  I use Debian on more systems than any other

Yet Debian makes it hard for people to help.  Like most software
engineers I simply don't have the time to waste on Debian's NM
process.  Debian's processes are indisputably Debian's decision
alone, but Debian has to live with the consequences ... falling
mindshare, orphaned packages, and slow releases.

Nevertheless, non-DD's can and do help by filing bug reports and
patches (upstream is best), helping people on d-u, and offering
constructive advice to DDs.  And one should not forget that most
of the software in Debian is developed and maintained by non-DD's.

--Mike Bird

