Portage rsync security
Florian Philipp <lists@f_philipp.fastmail.net> Thu, 20 Mar 2008 11:45:40 +0100
| Newsgroups | gmane.linux.gentoo.security |
|---|---|
| Message-ID | <1206009940.22869.11.camel@NOTE_GENTOO64.PHHEIMNETZ> |
Hi list! Am I right that there is currently no way portage tries to verify that the rsync-mirror is not spoofed? Doesn't that pose a major threat? If I were able to manipulate the domain name resolution, I could easily trick gentooers into making false updates and thus executing a malicious program with root-permission on their machine. So, why isn't there some kind of public key authentication going on, at least optionally? By the way: How does gentoo's gpg-feature work. The man-page doesn't contain an explanation.
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) iD8DBQBH4kBUqs4uOUlOuU8RAqCaAJ4tbou8YNM8OI7xPs5UdDZnQhniRQCbBOqv Pfao+64HWP1fIBaFi08JOSY= =VEoD -----END PGP SIGNATURE-----