Re: How secure is the openSUSE Build Service?



Am Mittwoch 07 November 2007 schrieb Eduardo Tongson:
Aniruddha was asking which is safer. There is a difference between 3rd
party repositories and official repositories. If you do not trust the
distribution's official repositories your alternative would be Linux
from Scratch and individually checking source tarballs.

Which is - of course - very impracticable. :)

I think it is *not* less secure. In the case of OSS it doesn't matter
anymore. When you trust several thousands developers around the globe,
hundreds of CVS, SVN, rsync, FTP, HTTP servers used for development and
dozens of distribution then *one* additional layer in the distribution
process doesn't really matter.

It is a matter of trust and not a matter of security.



--
Tom <tom@xxxxxxxxxxxxxxxxxx>
fingerprint = F055 43E5 1F3C 4F4F 9182 CD59 DBC6 111A 8516 8DBF



Relevant Pages

  • Re: How secure is the openSUSE Build Service?
    ... party repositories and official repositories. ... In the case of OSS it doesn't matter ... When you trust several thousands developers around the globe, ... that Alice really is Alice. ...
    (Focus-Linux)
  • Re: Mission Accomplished!
    ... It doesn't matter where I heard it. ... even it it turned out to be the one you trust. ... You may repeat after me the Chant of Holy Enlightenment: ... Smiths, as in the quickly multiplying clones from "Matrix". ...
    (rec.boats)
  • Re: The Bangalore meet
    ... It does not really matter what I find objectionable. ... I trust you and have responded because of that. ... trust strangers and ask a lot of questions in the beginning and only later ... their mouths absolutely shut if they don't feel like responding to you ...
    (rec.music.indian.misc)
  • Re: Mission Accomplished!
    ... It doesn't matter where I heard it. ... even it it turned out to be the one you trust. ... Let's start with any of the daily newspapers, television new stations, or ... did we *really* not have any airport security before we invaded Iraq? ...
    (rec.boats)
  • Re: some questions about high precesion constant current source
    ... Are you seeing thermal effects in your sense resistor? ... How well do you trust your meter? ... Getting .01% accuracy is not a matter of getting one thing ...
    (sci.electronics.design)