Gentoo Archives: gentoo-security

From: Kurt Lieber <klieber@g.o>
To: Koon <koon@××××××.net>
Cc: Jasmine CHUA <Jasmine.Chua@××××××××××××××××.com>, gentoo-security@l.g.o
Subject: Re: [gentoo-security] emerge sync
Date: Tue, 23 Mar 2004 10:11:44
Message-Id: 20040323101201.GW26101@mail.lieber.org
In Reply to: Re: [gentoo-security] emerge sync by Koon
1 On Tue, Mar 23, 2004 at 10:59:20AM +0100 or thereabouts, Koon wrote:
2 > A rsync mirror compromise could definitely lead to a security problem.
3 >
4 > This is a known problem that is being worked on, and some kind of
5 > digital signing check will be built into the ebuild release / rsync
6 > process someday...
7
8 For anyone subscribed to gentoo-dev, please see the message I just posted
9 there which details the problem as well as our lack of effort to solve it.
10 Hopefully, enough noise from the community will help give us a swift kick
11 in the butt and a wakeup call. (hint: that means you folks)
12
13 --kurt

Replies

Subject Author
Re: [gentoo-security] emerge sync Jesse Nelson <yoda@××××××.com>