Re: One for the Security Guru's

James Stevenson (james@stev.org)
23 Oct 2002 23:44:17 +0100


> Third, if they don't do it already, I'd like kpackage, gnorpm, and similar
> tools to always check signatures before loading a package. (And, for the GPG
> public keys used to have come with trust signatures from the installation
> CD.) That would really help with all the newbies to *nix coming on board
> now.

dont most of thoose only use a shared libary which would mean
1 file overwrite and disable all. Though rpm i know is normally static.

> PS: If you don't trust your gpg or rpm, boot off install CD # 1, switch to a
> text console, and use the ones on the CD. QED. :^)

heh by the time you dont trust it. Its normally time to reinstall.

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/