LWN.net Logo

Attacks on package managers

Attacks on package managers

Posted Apr 20, 2009 14:02 UTC (Mon) by robbe (guest, #16131)
In reply to: Attacks on package managers by aigarius
Parent article: Attacks on package managers

> If the attacker has such control over your infrastructure he could just
> as well block you from connecting to update sites completely [...]

A DOS like that is much easier to detect than freezing of the Release
file. You'd get an error message if the download site is not reachable --
but that it has no new updates is not a cause for an error.

FWIW, slowing the victim's clock to keep valid-for-one-week metadata
current for much longer (as discussed in the Debian bug) is also quite
noticable, normally.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds