1 |
On Sun, Sep 07, 2003 at 09:54:20PM +0000, Jan Krueger wrote: |
2 |
> On Sunday 07 September 2003 21:43, Jan Krueger wrote: |
3 |
> > No. I trust you. But trusting you doesnt mean that the ebuild you checked |
4 |
> > in to the tree arrives at my hardrive unmodified. There is no way for you |
5 |
> > as a human beeing to garantee this to me. Instead it should be expected |
6 |
> > that the ebuild gets modified (by faulty software/hardware/network/whatever |
7 |
> > or by a malicious attacker). So this must be taken care of. |
8 |
> I give you an example: |
9 |
> With so many gentoo-rsync hosts spread all over and the use of unencripted |
10 |
> rsync transfer a man in the middle attack (eg. by arp-spoofing or whatever), |
11 |
> that inserts an malicious ebuild along with digest and Manifest into the |
12 |
> rsync stream is very much imaginable to me. |
13 |
> |
14 |
> So i suggest to, as quickly as possible, establish the infrastucture to do |
15 |
> rsync over ssl/ssl or other secure transport. |
16 |
> |
17 |
|
18 |
GPG signing would take care of this issue. |
19 |
|
20 |
-- |
21 |
Jon Portnoy |
22 |
avenj/irc.freenode.net |
23 |
|
24 |
-- |
25 |
gentoo-dev@g.o mailing list |