LWN.net Logo

Numerous Debian Project systems compromised

Numerous Debian Project systems compromised

Posted Nov 21, 2003 21:01 UTC (Fri) by NAR (subscriber, #1313)
In reply to: Numerous Debian Project systems compromised by maceto
Parent article: Numerous Debian Project systems compromised

I don't know the system the Debian project uses to authenticate, etc. but the fact that there is 1200+ contributors doesn't mean that it's enough to break into one computer used by one of 1200+ contributors to wreak havoc in Debian?

Bye,NAR


(Log in to post comments)

Numerous Debian Project systems compromised

Posted Nov 21, 2003 21:10 UTC (Fri) by piman (subscriber, #8957) [Link]

(Long, random) LDAP passwords and SSH, and package uploads must be signed by GPG keys. Passwords are only emailed encrypted. Even if you have a developer's compromised home system, it's pretty hard to get things uploaded. And most developers don't have root or extra-privileged access to the machines.

Note also that auric, the main archive server, was not compromised at all.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds