[devel] [JT] *Kit

Michael Shigorin mike на osdn.org.ua
Вс Дек 13 22:49:25 UTC 2009


On Mon, Dec 14, 2009 at 01:44:28AM +0300, Vitaly Kuznetsov wrote:
> > In short, the problem was that in the Fedora 12 default
> > installation, regular users sitting at the console could install
> > signed packages from any repository that the administrator has
> > enabled. [...]
> Fedora is a "bleeding edge" and thus this is normal.

---
The Fedora project has likely learned quite a bit from this
particular controversy, and it seems to be taking the right steps
to avoid a repeat in the future. For a distribution that went
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
through a great deal of pain to integrate SELinux features in
order to increase the security of the system, it is mind-boggling
to many that this non-root install feature was added as the
default. There were multiple missteps--making it the default, not
highlighting it in the release notes, not testing it in Rawhide,
and so on--but those can all be corrected. Hopefully, the outcry
and publicity will ensure that the word gets out, so that Fedora
users will understand the issue and can make the appropriate
changes for their systems.

In the meantime, though, other projects--distributions or
software packages--would be well-served by studying this episode.
Security is hard, and requires great diligence. It is likely that
other projects could have hit this same kind of problem, but,
hopefully, with this incident as a guide, will avoid doing so
in the future.
---

-- 
 ---- WBR, Michael Shigorin <mike на altlinux.ru>
  ------ Linux.Kiev http://www.linux.kiev.ua/


Подробная информация о списке рассылки Devel