You are not logged in.

#1 2008-08-14 15:28:32

tntcoda
Member
Registered: 2007-07-24
Posts: 115

Pacman Security Question

Hi,

I was just wondering if Pacman is ever likely to have more security built into it? Specfically I mean a way to garentee that packages which are updated from a mirror are legitimate in origin. Maybe some kind of digital certificate signing of packages?

Say for example, your DNS was compromised, and thus you cannot trust the mirror pacman is using, a malicious 3rd party can now issue an update that would be installed by root, giving potential full control of a box.

Is anything likely to be added to combat this kind of attack? Or is there already something in place ive missed?

Thanks,

Jack

Offline

#2 2008-08-14 15:33:17

muczyjoe
Member
From: Szeged (Hungary)
Registered: 2007-05-16
Posts: 45
Website

Re: Pacman Security Question

I'm interested too. Devs?

Offline

#3 2008-08-14 15:38:05

Allan
Pacman
From: Brisbane, AU
Registered: 2007-06-09
Posts: 11,472
Website

Re: Pacman Security Question

There is a bug report about it (http://bugs.archlinux.org/task/5331) and a start has been made on adding package signing to makepkg/pacman (http://code.toofishes.net/gitweb.cgi?p= … /heads/gpg) although I'm not sure how complete it is.

Offline

#4 2008-08-14 15:38:07

skottish
Forum Fellow
From: Here
Registered: 2006-06-16
Posts: 7,942

Re: Pacman Security Question

There has been discussion about this recently:

http://bbs.archlinux.org/viewtopic.php?id=51570

Offline

#5 2008-08-14 15:44:43

tntcoda
Member
Registered: 2007-07-24
Posts: 115

Re: Pacman Security Question

Interesting thanks guys, will have a read through them

Offline

#6 2008-08-14 22:26:02

toofishes
Developer
From: Chicago, IL
Registered: 2006-06-06
Posts: 602
Website

Re: Pacman Security Question

There has been a lot of talk and little action on this front. Feel free to come join us on the pacman-dev mailing list to discuss and contribute, but none of the current developers are really interested in making it happen.

Offline

Board footer

Powered by FluxBB