Gentoo Archives: gentoo-security

From: Koon <koon@××××××.net>
To: Jasmine CHUA <Jasmine.Chua@××××××××××××××××.com>
Cc: gentoo-security@l.g.o, jonathan.gill@××××××××××.com
Subject: Re: [gentoo-security] emerge sync
Date: Tue, 23 Mar 2004 09:59:45
Message-Id: 40600A78.3050504@thyone.net
In Reply to: [gentoo-security] emerge sync by Jasmine CHUA
1 Jasmine CHUA wrote:
2
3 > I am concerned with the security aspects of running an `emerge sync`. Is
4 > there any way to verify the packages to be downloaded from running an emerge
5 > sync? What if the gentoo rsync server gets hacked? Understanding that each
6 > ebuild comes with a md5 digest and all packages are safe in this manner but
7 > i see that still does not override the possibility that the rsync server may
8 > get hacked?
9
10 A rsync mirror compromise could definitely lead to a security problem.
11
12 This is a known problem that is being worked on, and some kind of
13 digital signing check will be built into the ebuild release / rsync
14 process someday...
15
16 -K
17
18 --
19 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] emerge sync Kurt Lieber <klieber@g.o>