[maemo-developers] [OT] maemo settings website

From: Steve Greenland steveg at moregruel.net
Date: Sun Nov 4 20:03:34 EET 2007
According to vicente garcia <vicentegarcia at gmail.com>:
> This website shows the package versions:
> 
> https://maemo.org/midcom-exec-midcom/about.php
> 
> I think it is unsecure to show this.

Well, all I get is a login page. But assuming that the if you do login
you get a list of midgard and associated package versions, it's not a
particular security issue. Script kiddies don't break websites by screen
scraping version numbers, they break websites by running their crack
scripts against every port 80 they can find. Otherwise my server logs
wouldn't be full of attacks against Windoze servers.

Contrariwise, you don't keep a site secure by hiding version numbers,
you keep a site secure by fixing the bugs.

Steve


-- 
Steve Greenland
    The irony is that Bill Gates claims to be making a stable operating
    system and Linus Torvalds claims to be trying to take over the
    world.       -- seen on the net


More information about the maemo-developers mailing list