Comment 104 for bug 44335

Revision history for this message
Nikil Mehta (nikil.mehta) wrote :

This is still pissing me off so another note on this...

There are potentially MILLIONS of users out there using this program and submitting their gmail password in cleartext. Jean-Yves Lefort, somebody wrote the gnutls code FOR you! I don't think you care about the security of the patch (aka your "reputation")- if you cared about security you would try to make sure that the majority of users out there are using your program in a secure manner. The fact is you don't care about security, you care about winning an argument with the Ubuntu/Debian maintainers. Which chances are you are not going to win.

And to those maintainers... this package is insecure enough that it shouldn't even be packaged and supported if you're not going to allow for OpenSSL compilation. Just remove it or allow for SSL. Seriously.