LWN.net Logo

An update on the Fedora August 2008 intrusion

An update on the Fedora August 2008 intrusion

Posted Mar 31, 2009 17:04 UTC (Tue) by chaneau (guest, #6674)
In reply to: An update on the Fedora August 2008 intrusion by tialaramex
Parent article: An update on the Fedora August 2008 intrusion

If this Fedora contributor ran Fedora, they had the option to enter their SSH passphrase as infrequently as once per (desktop) login. Is that too much?

That's the missing answer from this report is it not? How did the intruder gain access to the private key in the first place?

Did the intruder have physical access?

Did he access the key remotely?

Did the Fedora guy leave his key on some untrusted computer?

Was the computer stolen?

Some of these questions are more frightening than the others, but if you want me to trust Fedora, the quality and the seriousness of it's administrators, they should tell us what really happened


(Log in to post comments)

An update on the Fedora August 2008 intrusion

Posted Apr 9, 2009 18:44 UTC (Thu) by eric.rannaud (guest, #44292) [Link]

That's the right question to ask. Can we get comments from Fedora people?

How was the private key first acquired?

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds