Re: Torrent tracker problem

2014-07-14 Thread Adam D. Barratt
On Mon, 2014-07-14 at 14:15 -0600, Kitty Cat wrote: > These torrents are not working with the Debian tracker. > > http://cdimage.debian.org/debian-cd/7.6.0/source/bt-cd/debian-update-7.6.0-source-CD-1.iso.torrent > > http://cdimage.debian.org/debian-cd/7.6.0/source/bt-cd/debian-update-7.6.0-sourc

Torrent tracker problem

2014-07-14 Thread Kitty Cat
These torrents are not working with the Debian tracker. http://cdimage.debian.org/debian-cd/7.6.0/source/bt-cd/debian-update-7.6.0-source-CD-1.iso.torrent http://cdimage.debian.org/debian-cd/7.6.0/source/bt-cd/debian-update-7.6.0-source-CD-2.iso.torrent Torrent Editor and also my Torrent softwa

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Michael Stone
On Mon, Jul 14, 2014 at 01:22:10PM -0400, Hans-Christoph Steiner wrote: Or, you could make use of the Check-Valid-Until and Min-ValidTime options in apt.conf. There's a reason things are done the way they are, and you probably aren't going to find a lot of interest in getting people to do a lot o

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Hans-Christoph Steiner
On 07/14/2014 01:12 PM, Michael Stone wrote: > On Mon, Jul 14, 2014 at 12:45:38PM -0400, Hans-Christoph Steiner wrote: >> One place that this will help a lot is managing completely offline machines, >> like machines for running secure build and signing processes. Right now, in >> order to instal

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Hans-Christoph Steiner
On 07/14/2014 12:59 PM, Paul Wise wrote: > On Tue, Jul 15, 2014 at 12:45 AM, Hans-Christoph Steiner wrote: > >> I'd like to contribute to this effort > > First thing is to get #733029 fixed, which involves disabling signing > by default (signing should be done after testing not before) and > ad

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Michael Stone
On Mon, Jul 14, 2014 at 12:45:38PM -0400, Hans-Christoph Steiner wrote: One place that this will help a lot is managing completely offline machines, like machines for running secure build and signing processes. Right now, in order to install a package securely on an offline machine, I have to ma

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Paul Wise
On Tue, Jul 15, 2014 at 12:45 AM, Hans-Christoph Steiner wrote: > I'd like to contribute to this effort First thing is to get #733029 fixed, which involves disabling signing by default (signing should be done after testing not before) and adding a signing tool to dpkg-dev. Then debsign/debuild ne

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Hans-Christoph Steiner
On 07/14/2014 12:31 PM, Paul Wise wrote: > On Tue, Jul 15, 2014 at 12:24 AM, Hans-Christoph Steiner wrote: > >> I agree that .deb packages should be individually signed > ... >> This has been discussed in the past. I really think it is just a >> matter of someone doing the work. > > The work h

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Paul Wise
On Tue, Jul 15, 2014 at 12:24 AM, Hans-Christoph Steiner wrote: > I agree that .deb packages should be individually signed ... > This has been discussed in the past. I really think it is just a > matter of someone doing the work. The work has been done many years ago and has been in the archive

Re: concrete steps for improving apt downloading security and privacy

2014-07-14 Thread Hans-Christoph Steiner
I agree that .deb packages should be individually signed, but I don't think that the current apt system is vulnerable to package corruption. Having a signature in the .deb. would make things a lot more flexible in terms of distribution because a .deb could be verified no matter how it ends up on

Re: Missing ISO hash

2014-07-14 Thread Cyril Brulebois
Djones Boni <07ea86b...@gmail.com> (2014-07-14): > The Debian 7.6 update ISO hashes are missing on bt-dvd directory. > http://cdimage.debian.org/debian-cd/7.6.0/amd64/bt-dvd/MD5SUMS > http://cdimage.debian.org/debian-cd/7.6.0/*/bt-dvd/MD5SUMS > > They can be found in iso-dvd and jigdo-dvd. > http:

Missing ISO hash

2014-07-14 Thread Djones Boni
The Debian 7.6 update ISO hashes are missing on bt-dvd directory. http://cdimage.debian.org/debian-cd/7.6.0/amd64/bt-dvd/MD5SUMS http://cdimage.debian.org/debian-cd/7.6.0/*/bt-dvd/MD5SUMS They can be found in iso-dvd and jigdo-dvd. http://cdimage.debian.org/debian-cd/7.6.0/amd64/iso-dvd/MD5SUMS ht