Re: securing a unix system - suggestions on checking for intrusions

Volker Kuhlmann <[email protected]>
Newsgroups gmane.org.user-groups.linux.new-zealand.general
Message-ID <[email protected]>
On Thu 06 Oct 2011 17:04:48 NZDT +1300, Jaco wrote:

> FYI - if the repo's poisoned, you're borked anyway:
> http://www.theregister.co.uk/2011/07/05/ftp_backdoor_shenanigans

That's just nonsense. It depends on whether the package was signed with
a secure key. If so, you're fine. I remember the time at about 1997 when
downloads cost $5/MB (uni, 3x that in town) from offshore but nothing
onshore, and I could fetch distro packages from any odd ftp server dodgy
or not, it didn't matter. At that time deb hadn't even heard of package
signing, or surely hadn't done anything about it.

Volker

-- 
Volker Kuhlmann			is list0570 with the domain in header.
http://volker.dnsalias.net/	Please do not CC list postings to me.

_______________________________________________
NZLUG mailing list [email protected]
http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.