Sure, could be - I really don't know. But I still tend to doubt that the same server is used
for both Fedora and Red Hat in their infrastructure for the functionality that was breached.
And given how much space was spent in the official summary about how the two breaches are
separate, I tend to presume we are talking about separate servers. But I hope that's
incorrect, and I presume we'll find out soon enough.
Posted Aug 22, 2008 16:37 UTC (Fri) by elanthis (subscriber, #6227)
[Link]
It could have been a single Red Hat employee who let his key or passphrase get stolen. If he
had access to both Red Hat and Fedora systems, well... there you go.
What happened with Fedora - and Red Hat too
Posted Aug 22, 2008 16:39 UTC (Fri) by Ed_L. (guest, #24287)
[Link]
I presume we will find out "soon enough" as well. However, given that in all likely hood RedHat/Fedora have the best security in the business, I would not presume we will find out before Red Hat quietly shares at least some details with its erstwhile competitors and sometime collaborators e.g. Debian, Gentoo, Mandriva, Canonical, Freespire, SuSE...
What happened with Fedora - and Red Hat too
Posted Aug 22, 2008 17:23 UTC (Fri) by drag (subscriber, #31333)
[Link]
Usually the human is the weakest link in any security system.
It's very likely that the attacker gained access to a account using social engineering or by
bad ssh habits on the part of a Fedora developer.