While I agree Debian is a fair choice in terms of security, I disagree with your reasoning. The “encryption bypass” is rather a minor vulnerability (i.e. if attacker has all prerequisities to abuse it, she probably could also perform another attacks) and I don't believe that this is statistically significant. On the other hand, there are also some Debian-specific vulnerabilities. For example, recent APT vulnerability or not-so-recent vulnerable SSH keys due to some Debian-specific tuning. This does not suggest that Debian is less secure, this suggests it is not so clear.
Regards, Vít Šesták 'v6ak' -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/63a67ab8-0e3d-445e-b22a-d79b7acf3a97%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
