Re: Testers required: PXE boot Slackware installers from slackware.org.uk
/dev/rob0 <[email protected]>
| Newsgroups | gmane.linux.slackware |
|---|---|
| Organization | RTFM |
| Message-ID | <[email protected]> |
On Sat, Jul 26, 2014 at 05:19:58PM +0200, Bengt Richter wrote
regarding fear of PXE boot over the Internet:
> Well, at least you'll separate the trusting from the paranoids ;-)
Probably everyone here knows Darren as well as I do, but for the
record I'll vouch for his character.
He's twisted and sick. He eats little babies for breakfast.
But this isn't about baby sitting, this is about trusting him as a
PXE boot source. Of course he is a professional and is perfectly
honourable in his intentions toward your computers.
That said, while I would absolutely trust Darren for this, it does
seem like a good opportunity for a MITM attack. Do you trust your
(or his) ISP/upstreams? Do you trust your (or his) national gov't?
It would be prudent to check the installer's gpg. Is there a way to
validate that online? If you know you're not using a trojaned gpg,
the signature verifications on the packages would confirm that you
are getting clean, genuine Slackware.
PS: No need to hurry to call the nice young men in the clean white
coats. I'm only saying that MITM would be possible, not that
it's likely in any way.
--
http://rob0.nodns4.us/
Offlist GMX mail is seen only if "/dev/rob0" is in the Subject: