Defence in Depth
Defence in Depth
Posted Jul 31, 2026 15:30 UTC (Fri) by davecb (subscriber, #1574)In reply to: Time-based tokens by archaic
Parent article: Arch Linux disables AUR package adoption
No one defence is likely to suffice. The "Orange Book" specified at least a secure login channel, covert-channel blocking, categories (like "my company") and security levels like unclassified, confidential and secret.
The last of those didn't help a lot, but the others made it hard to even get to that point.
The last of those didn't help a lot, but the others made it hard to even get to that point.
So fixing the tokens is a worthwhile part of a comprehensive suite of guards.
