Re: Need for security model

Mark Bainter <[email protected]> Sat, 13 Dec 2003 14:17:29 -0600
Newsgroups gmane.linux.zynot.general
Message-ID <[email protected]>
--===============1185165845==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="jRHKVT23PllUwdXP"
Content-Disposition: inline


--jRHKVT23PllUwdXP
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Low Zhen Lin [[email protected]] wrote:
>=20
> On Tuesday, December 9, 2003, at 04:11  AM, Chris Frey wrote:
>=20
> >On Sun, Dec 07, 2003 at 12:48:36AM +0800, Low Zhen Lin quoted a spec:
> Much of that. It is the build manager, download manager, package=20
> manager among some other things. It will be distributable, meaning, you=
=20
> can run the components on different computers, but it will be able to=20
> form one coherent whole.

Will it also be componantized?  I.e., split into many pieces and
strung together to build the application?  Or will it be a monolithic
piece split into a couple of sections that can be run seperately?

> >I would prefer this integrity to rely on as few points of failure as
> >possible: i.e. something like a developer-signed XBuild, and not
> >something that ever relies on the security of the server or mirrors
> >holding the data.
>=20
> As few? I'd rather install integrity checks at every point possible.

I think you need to reread what he said.  He wants "as few points of
failure" as possible.  That doesn't amount to fewer integrity checks.

> >>~    * Confidentiality: Protect data in transit against eavesdropping.
> >Sounds good, but seems to me to be more of a fluff feature, for what
> >I imagine Xeta being used for.  Does it matter if someone is able
> >to sniff the wire and find out I installed the latest binutils?
> >I'm willing to be convinced that it does matter, but so far can't
> >class it as a critical need.
>=20
> No... But they could use the information that you're about to start a=20
> KDE compile on the webserver and launch a DDOS attack. You're right=20
> that this is not a critical need... But what is one to do when the PHB=20
> says, nothing leaks out of the computer network?

And what about people who sniff and see that you are pulling down the
security update to package y, meaning you're probably upgrading because
you're vulnerable to the remote root vulnerability that was just=20
announced?


--jRHKVT23PllUwdXP
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE/23PZ4SLMBKXes28RAp0DAJoCPvfXELCpAmuZ4ftyzsiLCdIpmgCcDsbH
v702j/48bg6GreHz1M1EjRw=
=XQcQ
-----END PGP SIGNATURE-----

--jRHKVT23PllUwdXP--

--===============1185165845==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Xeta mailing list
[email protected]
http://lists.zynot.org/mailman/listinfo/xeta

--===============1185165845==--