Re: Reflections on Trusting Trust

From: Kris Kennaway (kris_at_obsecurity.org)
Date: 11/30/05

  • Next message: Peter C. Lai: "Re: Reflections on Trusting Trust"
    Date: Wed, 30 Nov 2005 04:02:48 -0500
    To: ?d?m Szilveszter <adamsz@mailpont.hu>
    
    
    

    On Wed, Nov 30, 2005 at 09:55:24AM +0100, ?d?m Szilveszter wrote:
    > On Sze, November 30, 2005 12:43 am, Colin Percival mondta:
    > > Even before you get to that point, you have to worry about making sure
    > > that the build clients are secure. One possibility which worries me a
    > > great deal is that a trojan in the build code for a low-profile port
    > > (e.g., misc/my-port-which-nobody-else-uses) could allow an attacker to
    > > gain control of a build client (and then insert trojans into packages
    > > which are built there).
    >
    > Which practically begs the question: could we, pretty please, change the
    > defaults and stop encouraging people from downloading distfiles and
    > compiling them when using the ports tree as *root*? (shudder) There is
    > exactly zero reason for this that I can think of apart from some "well
    > it's more convenient that way" arguments.

    And of course that some ports don't build as non-root :-)

    If you're willing to fix them (there may be a lot), I could schedule a
    full port build done as non-root so you can start work.

    Kris

    
    



  • Next message: Peter C. Lai: "Re: Reflections on Trusting Trust"

    Relevant Pages

    • Whos blocking these ports? Please help...
      ... server - one is called Vicomsoft Internet Gateway (proxy server, ... IG basically takes over the TCP/IP routing and does this using ... Each of these ports uses a NIC in the server. ... All the clients are assigned IPs ...
      (microsoft.public.win2000.security)
    • Re: Firewall advice
      ... > The VPN will only way for outside users to connect. ... old ipchains you'd be allowing inbound on the unpriv'd ports anyway. ... You'll need to let 3389 in from the PPTP sessions. ... IP's if only a few clients) to route through. ...
      (comp.security.firewalls)
    • Re: newbie with www user security problem
      ... The box is secure that much i have found out. ... everyone passwords on the box. ... i am in the process of upgrading the ports now and there are problems ... page and more customization. ...
      (FreeBSD-Security)
    • Re: Open Ports
      ... want the ports open even ifs all in house and behind the hardware firewall??? ... it opens up in demo mode. ... server is Cisco Catalyst Express 500 switches for voice over IP. ... will take requests from the clients. ...
      (microsoft.public.windows.server.general)
    • Re: Election Poll
      ... against a nuclear attack or a "dirty bomb". ... There is NO way to secure our ports from said attacks or bombs. ...
      (alt.machines.cnc)