LWN.net Logo

On the security of our processes and infrastructure

On the security of our processes and infrastructure

Posted Sep 9, 2011 16:39 UTC (Fri) by JoeBuck (subscriber, #2330)
In reply to: On the security of our processes and infrastructure by Klavs
Parent article: On the security of our processes and infrastructure

No, it wouldn't help. If the developer's system is compromised, the rootkit could see and intercept every action. The rootkit would simply wait for the developer to sign a commit, and then apply that signature to a different commit. The fact that the developer also had to enter a token from a smartcard or get her iris scanned is no defense if someone else owns the developer's machine.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds