Gentoo Logo
Gentoo Spaceship




Note: Due to technical difficulties, the Archives are currently not up to date. GMANE provides an alternative service for most mailing lists.
c.f. bug 424647
List Archive: gentoo-security
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-security@g.o
From: Russell Valentine <russ@...>
Subject: Re: Thoughts on Package Security
Date: Wed, 18 Feb 2004 16:49:49 -0600
On Wed, 18 Feb 2004 10:51:35 -0700
will.richey@... wrote:

> emerge -u xyzzy:
>  - get source package from actual distributor, NOT GENTOO
>  - compare MD5 of that to MD5 hash in portage tree
>  - continue ebuild
> 
> So, the MD5 hash in the portage tree comes from a different server
> than the source package.  So, the determined attacker would have to
> control considerable more than one site.

One could specify a different file to download. It wont find the file on a
Gentoo mirror and will download it from where it is specified in the
ebuild. Also I could care less if it actually downloads the real file. The
ebuild could patch the code or do many other things. The ebuilds,
packages, and patches need to be signed in some way. Then you just have to
trust the developers and that no keys get stolen. Or you can check
everything before you install something.


Russell Valentine
Attachment:
pgpXoIPLYmLeS.pgp (PGP signature)
References:
Thoughts on Package Security
-- Brian Klauss
Re: Thoughts on Package Security
-- guerrilla_thought
Re: Thoughts on Package Security
-- Heikki Levanto
Re: Thoughts on Package Security
-- Brian Klauss
Re: Thoughts on Package Security
-- Ed Grimm
Re: Thoughts on Package Security
-- will . richey
Navigation:
Lists: gentoo-security: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: Thoughts on Package Security
Next by thread:
Re: Thoughts on Package Security
Previous by date:
Re: Thoughts on Package Security
Next by date:
Re: grSecurity Information


Updated Jun 17, 2009

Summary: Archive of the gentoo-security mailing list.

Donate to support our development efforts.

Copyright 2001-2013 Gentoo Foundation, Inc. Questions, Comments? Contact us.