1 |
2015-03-06 1:56 GMT+01:00 Rick "Zero_Chaos" Farina <zerochaos@g.o>: |
2 |
> |
3 |
> tl;dr webrsync-gpg is a built in feature of the package manager which |
4 |
> OPTIONALLY adds a significant amount of security against the attacks |
5 |
> described on your website. This is not currently the default setting, |
6 |
> however, it is described in many hardening guides for gentoo and widely |
7 |
> used among the security conscious. |
8 |
|
9 |
On 03/06/15 08:53, Mark Kubacki wrote: |
10 |
> |
11 |
> Without numbers backing that up this is speculation. |
12 |
|
13 |
2015-03-06 16:20 GMT+01:00 Rick "Zero_Chaos" Farina <zerochaos@g.o>: |
14 |
> |
15 |
> 5,7,16,38,42. There are some numbers to back up what I'm saying. I |
16 |
> have been doing security work for over 15 years and I'm a professional |
17 |
> pen-tester. If you want to read the portage code to verify what I said |
18 |
> that's fine, but I'm reasonably confident I distilled what portage does |
19 |
> into english. |
20 |
|
21 |
We're on the same side here. |
22 |
|
23 |
Do we have numbers showing the ratio "portage used with defaults" vs. |
24 |
where "[webrsync-gpg] is described in many hardening guides for gentoo |
25 |
and widely used among the security conscious" applies? |
26 |
|
27 |
DNS not being encrypted is just painting the whole picture. Point is, |
28 |
the default is that "emerge --sync" results in a transfer using RSYNC |
29 |
(or http). |
30 |
|
31 |
And by default you cannot compare the result with any authoritative source. |
32 |
|
33 |
-- |
34 |
Mark |