1 |
On Sunday 07 September 2003 21:43, Jan Krueger wrote: |
2 |
> No. I trust you. But trusting you doesnt mean that the ebuild you checked |
3 |
> in to the tree arrives at my hardrive unmodified. There is no way for you |
4 |
> as a human beeing to garantee this to me. Instead it should be expected |
5 |
> that the ebuild gets modified (by faulty software/hardware/network/whatever |
6 |
> or by a malicious attacker). So this must be taken care of. |
7 |
I give you an example: |
8 |
With so many gentoo-rsync hosts spread all over and the use of unencripted |
9 |
rsync transfer a man in the middle attack (eg. by arp-spoofing or whatever), |
10 |
that inserts an malicious ebuild along with digest and Manifest into the |
11 |
rsync stream is very much imaginable to me. |
12 |
|
13 |
So i suggest to, as quickly as possible, establish the infrastucture to do |
14 |
rsync over ssl/ssl or other secure transport. |
15 |
|
16 |
Jan |
17 |
|
18 |
|
19 |
-- |
20 |
gentoo-dev@g.o mailing list |