1 |
On Mittwoch, 20. Juni 2007, Olivier Crête wrote: |
2 |
> |
3 |
> I will claim that almost any file in /etc is potentially sensitive (even |
4 |
> if it does not contain passwords, if may contain other informations |
5 |
> interesting to a cracker). And even if we did what you propose, we'd run |
6 |
> the risk of missing some and giving the user a false sense of security. |
7 |
> |
8 |
> Maybe we should document somewhere that the only way to make bin pkg |
9 |
> that are safe for public distribution is to do emerge -b or -B .. And |
10 |
> that pkgs built with quickpkg may contain sensitive information. |
11 |
|
12 |
If there is smart conf-file updating inside pkg_preinst(), I think even |
13 |
emerge -b could be unsafe. |
14 |
|
15 |
Matthias |
16 |
|
17 |
-- |
18 |
Matthias Schwarzott (zzam) |
19 |
-- |
20 |
gentoo-dev@g.o mailing list |