> We still can. We actually did and it is marked for further investigation.
(simplicity)
That is a pending issue, but what I meant was something else: The
possibility, ways, and remedies of institutional or intelligence attacks on
FOSS. That issue needs to be laid on the table and given a good in-depth
look.
> Sure but it is not always practical, e.g. in a work scenario...
Yes, but we still need to shrink exposure as much as we can. If your exposure
is too risky to mix it with your personal environment, then you simply
separate them (to separate laptops if need be). There is no perfect
compromise. This is also the same in everyday life.
> What measures? What is there to wait for?
Let me be emphatic with the FSF. We have invested such a money and man-months
in a browser to prune it, then someone tells us that it is leaking
information, and more importantly, it may be doing this on purpose. I.e. we
got an *expensive* baby in our arm that bites. It is all too easy to tell
them "just drop the baby". Then what? Before doing that, they have to
evaluate the alternatives, the costs involved, success probability, etc. If I
were FSF, I would simply put IceCat to "maintenance mode", and adopt Midori
(it *is* an excellent option) and iron out its bugs and start pushing Midori
in less than a year, offering IceCat in the mean time (don't forget that they
are running a large ship, not a canoe - they cannot quickly change direction
on whims).
What would you expect? RMS publicly stating that IceCat is crap, that it is
removed from GNU archives and endorsement list, that everyone should just
quit using it and instead just use what the heck they want..? Dropping IceCat
and adopting something else is very, *very* serious and expensive affair. And
as I have said, FSF is not a small canoe that can change directions on short
notice.
We need to wait and see what comes eventually off of your warning RMS about
IceCat. Just patience.