LWN.net Logo

Numerous Debian Project systems compromised

Numerous Debian Project systems compromised

Posted Nov 21, 2003 21:10 UTC (Fri) by piman (subscriber, #8957)
In reply to: Numerous Debian Project systems compromised by NAR
Parent article: Numerous Debian Project systems compromised

(Long, random) LDAP passwords and SSH, and package uploads must be signed by GPG keys. Passwords are only emailed encrypted. Even if you have a developer's compromised home system, it's pretty hard to get things uploaded. And most developers don't have root or extra-privileged access to the machines.

Note also that auric, the main archive server, was not compromised at all.


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds