|
|
Log in / Subscribe / Register

One week of infrastructure issues

One week of infrastructure issues

Posted Aug 21, 2008 0:23 UTC (Thu) by ofeeley (guest, #36105)
Parent article: One week of infrastructure issues

[...]none of us know what is going on [...]But Fedora's leadership appears to have failed here.
Although we've been "waiting and not seeing" for a week now it's still impossible to make such a judgement.
If Fedora users need to be concerned about the software running on their systems, they should have been told by now. If they can relax and stop worrying, they should have been told that as well.
Supposing it's a difficult to fix vulnerability affecting many parts of the Fedora infrastructure and although it's not believed that any packages were compromised it's still a small possibility and in order to quantify that possibility the exact details need to be shared which could lead to further attacks? All speculation is premature at this stage and certainly strong conclusions about failure of leadership is really pre-judging things.


to post comments

One week of infrastructure issues

Posted Aug 21, 2008 1:21 UTC (Thu) by sbergman27 (guest, #10767) [Link] (1 responses)

While I cannot know exactly what the problem is, it seems almost certainly to be serious and
security related.  It think it's a pretty fair guess that we are all actually waiting on Red
Hat Legal to make a decision regarding what should be made known, when it should be made
known, and how it should be phrased.  I'm very pro Red Hat.  But realistically, this could
turn out to be a *very* serious issue for them.  It's not their commercial product. But Red
Hat is ultimately liable for Fedora.

One week of infrastructure issues

Posted Aug 21, 2008 20:08 UTC (Thu) by smoogen (subscriber, #97) [Link]

Or its dealing with law enforcement on something. That is usually the biggest gag issue.

One week of infrastructure issues

Posted Aug 21, 2008 9:06 UTC (Thu) by liljencrantz (guest, #28458) [Link] (2 responses)

Not impossible at all, in my opinion. In what way would Fedora security be significantly
compromised by a short, non-specific statement explaining whether there is a chance that
packages that have been distributed to users have been compromised or not. Thats mainly what
people want to know. 

In fact, if there is a chance that packages that have been distributed to users have been
altered by a third party, it is extremely troubling that Fedora has not gone public with this
information.

One week of infrastructure issues

Posted Aug 21, 2008 11:18 UTC (Thu) by motk (subscriber, #51120) [Link] (1 responses)

... then it's probably not an issue then, or else they would have done so.

One week of infrastructure issues

Posted Aug 22, 2008 9:27 UTC (Fri) by liljencrantz (guest, #28458) [Link]

If that is the case, why have they not simply gone out and said that?

A simple statement along the lines of «We've had a major security breach, that we can not
disclose at this time. We have determined that packages distributed by the Fedora project have
not been compromised. You Fedora installation is not at risk. Please bare with us while we fix
this.» would put a lot of peoples mind at ease. Like the article said, this is a bit of a
failure to communicate from Fedoras leadership.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds