Gentoo Archives: gentoo-dev

From: hasufell <hasufell@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] ChangeLog
Date: Wed, 04 Nov 2015 16:18:53
Message-Id: 563A2FDC.1090801@gentoo.org
In Reply to: Re: [gentoo-dev] ChangeLog by Andrew Savchenko
1 On 11/04/2015 09:56 AM, Andrew Savchenko wrote:
2 > On Sun, 1 Nov 2015 14:53:20 +0100 hasufell wrote:
3 >>>> You shouldn't use rsync anymore, it is inherently insecure. The git
4 >>>> tree is _properly_ gpg signed so you can verify it's correctness.
5 >>>>
6 >>>> With the following portage configuration/hooks, any user can run the
7 >>>> tree directly from git:
8 >>>> https://github.com/hasufell/portage-gentoo-git-config
9 >>>
10 >>> More secure by fetching metadata cache via rsync ?
11 >>> Better by running egencache after each sync ?
12 >>> I don't think so.
13 >>>
14 >>
15 >> Yes it is.
16 >
17 > No, it is not. The whole git tree is insecure and no better than
18 > rsync or CVS in terms of data security because SHA1 is vulnerable.
19 >
20
21 Another one who is confusing _any_ collision with _preimage attack_ ;)

Replies

Subject Author
Re: [gentoo-dev] ChangeLog Kristian Fiskerstrand <k_f@g.o>
Re: [gentoo-dev] ChangeLog "Chí-Thanh Christopher Nguyễn" <chithanh@g.o>