https://bugs.freedesktop.org/show_bug.cgi?id=51819

--- Comment #19 from [email protected] ---
@Michael Meeks - thanks for your answer, but I think you clearly not understood
the severe of this bug.
To clear some point:
1. Security is not important only for me, it is important for everybody who
uses password-protection.
2. _I_ personally know how to circumvent this bug, but a lot of people does not
even dream of having such a big security hole in LO (for more than 1 year), so
they are totally helpless against it.
3. You advertised the encryption changes in 3.5 as "more secure", while it is
just the opposite, saving now a password-protected document every 10-15 minutes
completely unencrypted all over the file system.
4. I am pretty sure, that it would take only a 30-45 minute debugging session
for an experienced developer to find the hole and fix it (maybe just some false
flag set somewhere); and I am also almost sure, that nobody took the time to do
it from the dev team in the past 1,5 year.
5. I tried to download and compile the sources last year to fix this issue, but
it was anything else than easy or self-explaining. Maybe I will try again now,
but cannot promise anything.
6. If somebody without any dev. experience finds in LO a severe security issue,
than he has to fix it himself, or nothing happens? And even if he did it, would
you accept a security patch from anybody out there, outside of the core team?
Sorry, but it sounds a bit lame... (NSA sends its greetings)
7. Since 3.5 a lot of minor changes / improvements were made, so there were
clearly no resource problem to fix such an issue.
8. You did not even accept the proposed hard hack (a critical security bug!)
without even explaining why.
9. The users DO have the right to know about this issue, and I am pretty sure
that if they did, this bug would get a lot more noise and complaining.
10. I am just a regular user not a developer, but "to turn my passion into
something constructive here" I suggest you to take a look around bug 40006 and
bug 43868 and maybe in a short time this bug could be fixed at last without
further headaches.

-- 
You are receiving this mail because:
You are the assignee for the bug.
_______________________________________________
Libreoffice-bugs mailing list
[email protected]
http://lists.freedesktop.org/mailman/listinfo/libreoffice-bugs

Reply via email to