Re: [SECURITY] [DSA 2739-1] cacti security update

2013-08-22 Thread debian
Bonjour, Vous n'êtes pas sans savoir que nous sommes en période de congés. Il se trouve que, pour mon plus grand plaisir, les miens sont en ce moment, malheureusement pour vous, celui où vous estimez nécessaire de devoir me contacter. Je ne pourrai donc vous répondre que début septembre. Merci d

Re: Compromising Debian Repositories

2013-08-22 Thread Paul Henning
Nope, not gonna do that. He can come right out and deny it himself, so it's on record. He's had weeks to do it and except for one personal reply has been tight lipped about it. Furthermore, I'm curious how that sabotage got by for 2+ years (thanks for correcting me Kurt) before it was discovered?

Re: Compromising Debian Repositories

2013-08-22 Thread kloschi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Probably parts of the answer lie in deterministic builds, see below. hth. best, kloschi - Original Message Subject: [liberationtech] Deterministic Builds Part One: Cyberwar and Global Compromise Date: Thu, 22 Aug 2013 10:39:56 +00

Re: Compromising Debian Repositories

2013-08-22 Thread adrelanos
Timo Juhani Lindfors: > adrelanos writes: >> Some Debian maintainers are working on deterministic builds, although >> they call it reproducible builds, that's great! Link: >> https://wiki.debian.org/ReproducibleBuilds > > Terminology is hard :) As mentioned in the bof we can make sure that the >

Re: Compromising Debian Repositories

2013-08-22 Thread Jonathan Wiltshire
On 2013-08-05 22:07, Paul Henning wrote: he was either threatened or paid - probably the latter - to cripple the entropy on by the NSA, and they've had a war on randomness for a long time now. That is an extremely serious accusation and one that you haven't backed up at all. If you hold some e