Gentoo Archives: gentoo-dev

From: Matthias Schwarzott <zzam@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] how to handle sensitive files when generating binary packages
Date: Wed, 20 Jun 2007 13:18:22
Message-Id: 200706201515.20684.zzam@gentoo.org
In Reply to: Re: [gentoo-dev] how to handle sensitive files when generating binary packages by "Olivier Crête"
1 On Mittwoch, 20. Juni 2007, Olivier Crête wrote:
2 >
3 > I will claim that almost any file in /etc is potentially sensitive (even
4 > if it does not contain passwords, if may contain other informations
5 > interesting to a cracker). And even if we did what you propose, we'd run
6 > the risk of missing some and giving the user a false sense of security.
7 >
8 > Maybe we should document somewhere that the only way to make bin pkg
9 > that are safe for public distribution is to do emerge -b or -B .. And
10 > that pkgs built with quickpkg may contain sensitive information.
11
12 If there is smart conf-file updating inside pkg_preinst(), I think even
13 emerge -b could be unsafe.
14
15 Matthias
16
17 --
18 Matthias Schwarzott (zzam)
19 --
20 gentoo-dev@g.o mailing list

Replies