[Gllug] Yet another M$ worm!

Doug Winter doug at pigeonhold.com
Tue Sep 23 13:30:51 UTC 2003


On Tue 23 Sep Paul Weaver wrote:
> I doubt many linux users would fall for an email from Linus patching the 
> latest kernel - however I do worry about a (man in the middle?) attack on 
> debian's apt servers. I just run apt-get update && apt-get upgrade every so 
> often, if someone had cracked the servers a lot of people would get infected 
> before reading the usual sites/email lists. 

Signature checking is being built into the various bits of apt, last i
heard.  Since all packages are signed by the DD who uploaded them, this
isn't rocket science.  It's a tad irritating it's not there already
really.

doug.

-- 
6973E2CF print 2C95 66AD 1596 37D2 41FC  609F 76C0 A4EC 6973 E2CF
"If you are the type of person who likes assault weapons, there
is a place for you - the United States Army. We have them."
   -- General Wesley Clark, responding to a question on gun control

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 240 bytes
Desc: not available
URL: <http://mailman.lug.org.uk/pipermail/gllug/attachments/20030923/18748785/attachment.pgp>
-------------- next part --------------
-- 
Gllug mailing list  -  Gllug at linux.co.uk
http://list.ftech.net/mailman/listinfo/gllug


More information about the GLLUG mailing list