1 |
Jasmine CHUA wrote: |
2 |
|
3 |
> I am concerned with the security aspects of running an `emerge sync`. Is |
4 |
> there any way to verify the packages to be downloaded from running an emerge |
5 |
> sync? What if the gentoo rsync server gets hacked? Understanding that each |
6 |
> ebuild comes with a md5 digest and all packages are safe in this manner but |
7 |
> i see that still does not override the possibility that the rsync server may |
8 |
> get hacked? |
9 |
|
10 |
A rsync mirror compromise could definitely lead to a security problem. |
11 |
|
12 |
This is a known problem that is being worked on, and some kind of |
13 |
digital signing check will be built into the ebuild release / rsync |
14 |
process someday... |
15 |
|
16 |
-K |
17 |
|
18 |
-- |
19 |
gentoo-security@g.o mailing list |