Gentoo Archives: gentoo-security

From: Dan Margolis <krispykringle@g.o>
To: Andreas Waschbuesch <awaschb@××××.de>
Cc: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Re: Trojan for Gentoo, part 2
Date: Sun, 07 Nov 2004 17:53:00
Message-Id: 418E60E5.1030405@gentoo.org
In Reply to: Re: [gentoo-security] Re: Trojan for Gentoo, part 2 by Andreas Waschbuesch
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Andreas Waschbuesch wrote:
5 > I could open some - as ist seems - "usefull" sourceforge-project and
6 > inject any "additional" code on gentoo systems, while submitting a
7 > perfectly "legal" ebuild, signed to "heavenly" trust.
8
9 The point is that if we implement signing, a user can say, ``Well, I
10 distrust the authors of this sourceforge project'' if they wish. But if
11 we do not, they may trust the authors and yet still not be able to trust
12 the source.
13
14 So the reasonable, expected behavior from portage is that the source
15 downloaded is the source it claims to be. If we do not trust the
16 original source, we needn't install the package, but if we do, we should
17 be able to trust the package implicity. Right now, we cannot trust the
18 package, even if we trust the original authors. Signing fixes this problem.
19
20 Again, this is like saying that since we have not had the NSA conduct
21 background checks on each and every open source developer, we should not
22 trust their products. Well, fine, then don't install them. But if you
23 decide you trust the folks at kernel.org, or KDE, or GAIM, or whatever,
24 you should be able to trust the vanilla-sources ebuild, or the kde
25 ebuild, or the gaim ebuild. Right now, you cannot. So even when one does
26 choose to trust upstream, he cannot trust portage. That is broken.
27
28 - --
29 Dan "KrispyKringle" Margolis
30 Security Coordinator/Audit Project, Gentoo Linux
31 -----BEGIN PGP SIGNATURE-----
32 Version: GnuPG v1.2.4 (Darwin)
33
34 iQEVAwUBQY5g5LDO2aFJ9pv2AQKDSAf+KXpMW/CTzVAp3KZjVoPHuHlWutd8U+l1
35 2NbsMvHEp0dJ4LBPakw48m4Py5jBm8ZkCxLFbo4kd1T1RczDXanuT9ou1K6+qQSk
36 MhEOG+LD/71h+S5NRZUkoaDBhCTPtnXRVlP3SRNSZS2/AxlBWB5wv8U7W/V5i/Fk
37 0klyGfpCSlx9OjR5X1itX4opYd30HP57TTIKuqV0OEgonkHmPR91bJhYo468W5Yc
38 ujz942WmMxuGawjDH163QmABegLbV++tgBJqiyXYguobxOEVRWCoaaJh4PfGvdVd
39 Ce3QyrpVKYavlc8eHUkyLWF8yaBSD4BsBLUGLAvWfnfOc2zDAwbPQg==
40 =5OuB
41 -----END PGP SIGNATURE-----
42
43 --
44 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Re: Trojan for Gentoo, part 2 "Chocron J." <chocronjl@××××.fr>
Re: [gentoo-security] Re: Trojan for Gentoo, part 2 Andreas Waschbuesch <awaschb@××××.de>