Gentoo Archives: gentoo-dev

From: "Olivier CrĂȘte" <tester@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] how to handle sensitive files when generating binary packages
Date: Wed, 20 Jun 2007 13:07:29
Message-Id: 1182344680.7336.18.camel@TesterBox.tester.ca
In Reply to: [gentoo-dev] how to handle sensitive files when generating binary packages by Mike Frysinger
1 On Wed, 2007-20-06 at 00:47 -0400, Mike Frysinger wrote:
2 > there are many files out there that contain critical information about your
3 > system ...
4
5 > however, there are certainly cases where the admin fully knows what they're
6 > doing and they want to create a binary package of their system with these
7 > sensitive files ... so where to meet in the middle.
8
9 > any other potential ideas ? (pretend my idea here isnt the greatest thing
10 > since Robot Chicken)
11
12 I will claim that almost any file in /etc is potentially sensitive (even
13 if it does not contain passwords, if may contain other informations
14 interesting to a cracker). And even if we did what you propose, we'd run
15 the risk of missing some and giving the user a false sense of security.
16
17 Maybe we should document somewhere that the only way to make bin pkg
18 that are safe for public distribution is to do emerge -b or -B .. And
19 that pkgs built with quickpkg may contain sensitive information.
20
21 --
22 Olivier CrĂȘte
23 tester@g.o
24 Gentoo Developer

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies