Re: Apt-get is insecure

2001-12-13 Thread Alexander Karelas
unsuccessful: "E: Couldn't find package debsign" On Thu, Dec 13, 2001 at 04:24:47PM +0100, Wichert Akkerman wrote: > Previously Alexander Karelas wrote: > > RedHat uses a PGP signature scheme. What are we doing about it? > > apt-get install debsign >

Apt-get is insecure

2001-12-13 Thread Alexander Karelas
A poster on slashdot has done some interesting research on whether an ISP that co-operates with the FBI can insert a trojan horse in your Debian machine. He demonstrates that it is easy: http://slashdot.org/comments.pl?sid=24834&cid=2697504 RedHat uses a PGP signature scheme. What are we doing

Re: Apt-get is insecure

2001-12-13 Thread Alexander Karelas
unsuccessful: "E: Couldn't find package debsign" On Thu, Dec 13, 2001 at 04:24:47PM +0100, Wichert Akkerman wrote: > Previously Alexander Karelas wrote: > > RedHat uses a PGP signature scheme. What are we doing about it? > > apt-get install debsign > --

Apt-get is insecure

2001-12-13 Thread Alexander Karelas
A poster on slashdot has done some interesting research on whether an ISP that co-operates with the FBI can insert a trojan horse in your Debian machine. He demonstrates that it is easy: http://slashdot.org/comments.pl?sid=24834&cid=2697504 RedHat uses a PGP signature scheme. What are we doing

shutdown via webpage

2001-11-29 Thread Alexander Karelas
How about if a webpage was made on the server that would require user authentication and would execute a suid shutdown CGI script?

shutdown via webpage

2001-11-29 Thread Alexander Karelas
How about if a webpage was made on the server that would require user authentication and would execute a suid shutdown CGI script? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]