View Single Post
Posts: 1,523 | Thanked: 1,997 times | Joined on Jul 2011 @ not your mom's FOSS basement
#101
Originally Posted by zimon View Post
Why move to technically and secure wise worse package format? Those may not had been the reasons why LSB and LinuxFoundation chose RPM, but nowadays they should be much stronger arguments than the political one that decision has been made.

Technically they are equal, but aren't, RPM supports transactions.
Secure wise they are equal, but aren't, because in practice the embedded GPS signatures in RPM is a better security policy.
google for MITM attack vulnerability
With a very high probability you meant GPG, not GPS. Also, rpm itself doesn't support transactions, but the Fedora package management does.

http://www.rpm.org/wiki/RpmLog

(You don't necessarily know what you talking about, do you?)