Re: One for the Security Guru's

James Stevenson (james@stev.org)
23 Oct 2002 23:17:01 +0100


> Be surprised: I run "gpg --verify foo.tgz.sign foo.tgz" every time I download
> from kernel.org. And, "rpm --checksig *.rpm" on stuff from redhat.com too.

and when an attacker looks into your .bash_history see this and modifies
gpg and rpm ?

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/