Numerous Debian Project systems compromised
Posted Nov 21, 2003 17:29 UTC (Fri) by
eludias (subscriber, #4058)
In reply to:
Numerous Debian Project systems compromised by Wummel
Parent article:
Numerous Debian Project systems compromised
I would advocate a number of enhancements to the Debian process (and other distro's):
- It has become time to have packages which you can install without having root privileges while running the install and deinstall scripts. Only a select number of packages would need them anyway. The only thing you need root priviliges for in a 'normal' package is for extracting your files, which is something which is checkable and containable.
- A network of 'package checkers' should exist, which compile Debian packages on their own and compare the compiled version with compiled versions on the servers. This should be distributed, so everyone who wanted to donate some CPU cycles and bandwith would be able to do so. Some kind of background task like SETI@home which would check a random package per day per computer or so. This would not help against source-code comprises, but it helps against trojaned binaries without knowing how it was trojaned.
(
Log in to post comments)