apt-get dist-upgrade wont break anything as long as you are using a stable package base in the sources.list. debian does NOT do any major version changes in stable, therefore any patches/updates most likely will not hurt anything. they also backport any fixes to the versions used in stable so you wouldnt be using the latest and greatest. cron'ing an apt-get upgrade from security.debian.org and also the normal mirror is a good idea in my opinion.
apt-get dist-upgrade wont break anything as long as you are using a stable package base in the sources.list. debian does NOT do any major version changes in stable, therefore any patches/updates most likely will not hurt anything. they also backport any fixes to the versions used in stable so you wouldnt be using the latest and greatest. cron'ing an apt-get upgrade from security.debian.org and also the normal mirror is a good idea in my opinion.
You can do a minimal install with most linux dists and probably with all the other bsd's which would probably lead to nothing being remotely vuln.
read the retraction dumbass
You sure they dont fear the fact millions of people are stealing their material. That could be part of it too. Just a thought.
Does it still break the RSA patent if you ship the package without using the RSAREF?