Gentoo Archives: gentoo-portage-dev

From: Mark Kubacki <wmark@×××××××××.de>
To: gentoo-portage-dev@l.g.o
Subject: Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers
Date: Fri, 06 Mar 2015 17:51:06
Message-Id: CAHw5crJLAFBJr5HGgm2wkW_t53qd-8r3xtfdWxNr-J3fGQNM7A@mail.gmail.com
In Reply to: Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers by "Rick \\\"Zero_Chaos\\\" Farina"
1 2015-03-06 1:56 GMT+01:00 Rick "Zero_Chaos" Farina <zerochaos@g.o>:
2 >
3 > tl;dr webrsync-gpg is a built in feature of the package manager which
4 > OPTIONALLY adds a significant amount of security against the attacks
5 > described on your website. This is not currently the default setting,
6 > however, it is described in many hardening guides for gentoo and widely
7 > used among the security conscious.
8
9 On 03/06/15 08:53, Mark Kubacki wrote:
10 >
11 > Without numbers backing that up this is speculation.
12
13 2015-03-06 16:20 GMT+01:00 Rick "Zero_Chaos" Farina <zerochaos@g.o>:
14 >
15 > 5,7,16,38,42. There are some numbers to back up what I'm saying. I
16 > have been doing security work for over 15 years and I'm a professional
17 > pen-tester. If you want to read the portage code to verify what I said
18 > that's fine, but I'm reasonably confident I distilled what portage does
19 > into english.
20
21 We're on the same side here.
22
23 Do we have numbers showing the ratio "portage used with defaults" vs.
24 where "[webrsync-gpg] is described in many hardening guides for gentoo
25 and widely used among the security conscious" applies?
26
27 DNS not being encrypted is just painting the whole picture. Point is,
28 the default is that "emerge --sync" results in a transfer using RSYNC
29 (or http).
30
31 And by default you cannot compare the result with any authoritative source.
32
33 --
34 Mark

Replies