LWN.net Logo

Study: Attacks on package managers

Study: Attacks on package managers

Posted Jul 15, 2008 2:20 UTC (Tue) by jmorris42 (subscriber, #2203)
In reply to: Study: Attacks on package managers by mdomsch
Parent article: Study: Attacks on package managers

Is there anything going to be done about the information disclosure problem?  Is there
anything that CAN be done about the information disclosure?

HTTPS connects can stop random points from noticing a host asking for an update but that won't
stop a mirror site itself from realizing that by asking for a package it means the requester
is running a previous version and is vulnerable.  Even a mirror on a 'reputable' network can
itself be compromised.  In the end the whole concept of mirrors depends on trusting unknown
machines.  Crypto can mitigate some of the more gross dangers but leaves a false sense of
security regarding more subtle risks.


(Log in to post comments)

Study: Attacks on package managers

Posted Jul 15, 2008 11:01 UTC (Tue) by tzafrir (subscriber, #11501) [Link]

This seems to be a high level of paranoia.

apt-tor, anybody?

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds