[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

https://bugs.gentoo.org/show_bug.cg i?id=597804 the gentoo

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 9
Thread images: 1

File: gentoo.png (5KB, 466x48px) Image search: [Google]
gentoo.png
5KB, 466x48px
https://bugs.gentoo.org/show_bug.cgi?id=597804

the gentoo meme is finished

remove the pinned post mods
>>
>>57308419
good. it's about time this meme died.
>>
>>57308419
tl;dr- packages (meaning both unprivileged apps and system services) are downloaded over an insecure, easily MITM-able connection. Digital signatures are available and are downloaded, and the fact that they are downloaded is presented to the user. The user therefore believes that their updates are being verified.

However these signatures are NOT actually being verified by Gentoo.

Possible solutions:
* Only use a secure connection to downloads the updates
* Always verify the digital signatures of the updates
* Preferably, both

This is unlikely to have a wide impact, because nobody in their right mind uses Gentoo in production (ChromeOS is based on it, but has its own security mechanisms) and nobody is interested in MITMing neckbeards' chinkpads.
>>
>>57308698
>damage control
>>
>>57308742
? I'm not defending it all. It's clearly been designed by people with absolutely no clue what they're doing when it comes to security. It's a joke.
>>
Why would anyone submit themselves to this shit when Funtoo exists?
>>
remember when we used to make fun of arch for not signing the package list? like 5 years ago?
>>
Why the fuck are they not using git yet.
>>
>>57309311
You can.
Thread posts: 9
Thread images: 1


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.