Hello Aaron!
12 Aug 2020 20:35, Aaron Thomas wrote to Benny Pedersen:
live updates, that breaks tripwire signatures, design of how wordpress
is secure is badly brokken, updates are fine if its done in normal spec
file f building binaries pkgs to be installed
Live updates for Wordpress or for plugins?
both
To me, it seems like a bad
idea regardless.
yes since gentoo have md5 of every installed file in portage, so basicly wordpress webupdate is designed to clue less we want updates, more or less maybe just how its creeamed in centos
You know how sometimes plugins start to conflict after an
update?
yes, words press is more stable if no webupdates or any update or even just new plugins is installed, to solve it all kind of plugins or even just themes must be in the tarball, so gentoo and other can verify md5 of every file installed
tripwire will be happy aswell there, but tripwire is just not needed with gentoo :)
What do you mean by normal spec file building?
take a 10Gb tarball custommize the spec file for what you need, then compile it and install the binaries compiled install, that way no one on remote can update it
I apologize, I don't understand that.
fair
at first i thinked its only a gentoo problem, but no its not, would
you replace a kernel with something builded at microsoft that clams is
latest
Who is doing that?
hopefully none
That sounds crazy!
Donald Trump is normal ?
Unless it's inadvertant?
maybe
I assume that none of us want to be dependent on Microsoft.
+1, i still have microsoft roms in my commodore 128 (basic), that is imho crime that it was alowed to be there without full asm source, commodore did not notice the risk of no more updates, it was silently killing old and good computer systems so microsoft could take another ride at new problems to solve
Regards Benny
... there can only be one way of life, and it works :)
--- Msged/LNX 6.1.2 (Linux/5.8.0-gentoo-r1-x86_64 (x86_64))
* Origin: I will always keep a PC running CPM 3.0 (2:230/0)