Main Contents

unthinkable paranoia

Planet Ubuntu

Internet is now proved to be unsecured even if DNS are patched and i reached and unthinkable level of paranoia. Given that launchpad ppa (which are awesome for QA) doesn’t use signed packages, so i can’t actually check the integrity of them i’ve changed all my sources.list from url’s to ip’s so i can’t (at least i hope) be vulnerable to cache poisoning \o/

P.S: Please launchpad team, make ppa use signed packages!

nxvl @ August 9, 2008

4 Comments

  1. Hobbsee August 10, 2008 @ 6:32 am

    Or, even better still…

    Please launchpad team, make it so that PPA packages can’t unwittingly be uploaded to the main archive!

    Sometimes I wonder if they even care about security…

  2. Greg August 10, 2008 @ 3:11 pm

    +1

  3. Asa August 11, 2008 @ 2:02 pm

    This idea has some good info on why PPAs aren’t signed. There are even more technical reasons why it doesn’t work, but I can’t remember where I read about them.

    http://brainstorm.ubuntu.com/idea/11810/

  4. ?????? November 28, 2008 @ 1:10 pm

    ???°?? ???? ?????µ – ?‚?µ???° ???°???????‹?‚?° ?‡?µ?‚????, ?????°?????±?? ?·?° ???????‚!

Leave a comment


Feed