View Single Post
Posts: 466 | Thanked: 418 times | Joined on Jan 2010
#13
Originally Posted by zimon View Post
I expect overall security to be better in Meego if it follows de facto RPM-distribution policy that all packages should be GPG-signed.
This current situation with Maemo and unsigned deb-package installations with wget+dpkg is intolerable, because also developers do it and one targeted MITM-attack can infect the whole community easily now without traces who did it.

I do not know if Meego and OpenSUSE has good SELinux support, but I hope Meego will get it. Fedora nowadays, after couple of years trial and error, has good SELinux-support and it is expected that all Fedora compatible RPM-packages are SELinux-aware.
Debian supports GPG signed packages as well, at least in Lenny+. Unfortunately most of Maemo 5 is built off of Debian Etch, so no GPG signing to be seen. This could easily be added though, so I don't know why it isn't.