LWN.net Logo

Study: Attacks on package managers

Study: Attacks on package managers

Posted Jul 14, 2008 21:12 UTC (Mon) by rahulsundaram (subscriber, #21946)
In reply to: Study: Attacks on package managers by rrdharan
Parent article: Study: Attacks on package managers

What kind of verification would you suggest for a voluntary mirror? If you add too much
overhead, good mirrors will just walk away and you will lose. That isn't the gateway where you
should be adding security. You should assume malicious mirrors are already present and work to
mitigate that within the distribution. 


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds