LWN.net Logo

Advertisement

Advanced thin client solution for Linux, based on Open Source. Mix Windows and Linux, 10 licenses for free!

Advertise here

Numerous Debian Project systems compromised

Numerous Debian Project systems compromised

Posted Nov 21, 2003 21:01 UTC (Fri) by NAR (subscriber, #1313)
In reply to: Numerous Debian Project systems compromised by maceto
Parent article: Numerous Debian Project systems compromised

I don't know the system the Debian project uses to authenticate, etc. but the fact that there is 1200+ contributors doesn't mean that it's enough to break into one computer used by one of 1200+ contributors to wreak havoc in Debian?

Bye,NAR


(Log in to post comments)

Numerous Debian Project systems compromised

Posted Nov 21, 2003 21:10 UTC (Fri) by piman (subscriber, #8957) [Link]

(Long, random) LDAP passwords and SSH, and package uploads must be signed by GPG keys. Passwords are only emailed encrypted. Even if you have a developer's compromised home system, it's pretty hard to get things uploaded. And most developers don't have root or extra-privileged access to the machines.

Note also that auric, the main archive server, was not compromised at all.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds