1 |
On Wed, 2007-20-06 at 00:47 -0400, Mike Frysinger wrote: |
2 |
> there are many files out there that contain critical information about your |
3 |
> system ... |
4 |
|
5 |
> however, there are certainly cases where the admin fully knows what they're |
6 |
> doing and they want to create a binary package of their system with these |
7 |
> sensitive files ... so where to meet in the middle. |
8 |
|
9 |
> any other potential ideas ? (pretend my idea here isnt the greatest thing |
10 |
> since Robot Chicken) |
11 |
|
12 |
I will claim that almost any file in /etc is potentially sensitive (even |
13 |
if it does not contain passwords, if may contain other informations |
14 |
interesting to a cracker). And even if we did what you propose, we'd run |
15 |
the risk of missing some and giving the user a false sense of security. |
16 |
|
17 |
Maybe we should document somewhere that the only way to make bin pkg |
18 |
that are safe for public distribution is to do emerge -b or -B .. And |
19 |
that pkgs built with quickpkg may contain sensitive information. |
20 |
|
21 |
-- |
22 |
Olivier CrĂȘte |
23 |
tester@g.o |
24 |
Gentoo Developer |