|
2010-03-20
, 21:47
|
|
Posts: 1,716 |
Thanked: 3,007 times |
Joined on Dec 2009
@ Warsaw, Poland
|
#232
|
The Following 2 Users Say Thank You to smoku For This Useful Post: | ||
|
2010-03-21
, 16:23
|
Posts: 1,341 |
Thanked: 708 times |
Joined on Feb 2010
|
#233
|
Here you are: https://garage.maemo.org/projects/moebian/
|
2010-03-21
, 18:10
|
Posts: 3,319 |
Thanked: 5,610 times |
Joined on Aug 2008
@ Finland
|
#234
|
That is one thing I have always disliked Debian systems, especially their deb-format. They do say authenticity and integrity is handled and no problems there, but developers still install deb packages blindly and cumulative security degradation can go through whole Linux community eventually. (see Thompson's trojan compiler)
At least that will be fixed with RPM-format in Meego as talked before.
http://fedoranews.org/tchung/gpg/
(later, when everything is set up, developer just builds automatically signed packages from spec-file or tarball or src.rpm-file.)
$ rpmbuild -ba --sign newpackage.spec
|
2010-03-23
, 01:03
|
Posts: 1,341 |
Thanked: 708 times |
Joined on Feb 2010
|
#235
|
I still understand what *package format* related security problem you're referring to. RPM and DEB are equal in that regard. If you choose not to sign your packages, or the user chooses not to validate them (or take into account the results of the validation), then yes, he's exposing himself to a security risk. Whether this happens with RPM or DEB makes no difference whatsoever.
I can understand people being more familiar/preferring one package format/manager, but please, please don't dismiss other formats because you're not familiar with them, it really helps no one.
|
2010-03-23
, 02:04
|
Posts: 149 |
Thanked: 140 times |
Joined on Sep 2009
@ YUL
|
#236
|
|
2010-03-23
, 03:18
|
Posts: 1,341 |
Thanked: 708 times |
Joined on Feb 2010
|
#237
|
I frankly have a headache after reading through this technical discussion. I would like to understand nonetheless. What is the security threat to my computer if only install application from the official Debian repos ?
What is the purpose of signing package then ? Is that not something useful only to third party developers and/or when there is no official repo ? All this to say I really don't see the point of a "GPG-signature like feature" for a distro like Debian (and will gladly plaid my ignorance on the subject).
Is there an example of a major distro switching from deb to rpm ?
The Following User Says Thank You to zimon For This Useful Post: | ||
|
2010-03-24
, 19:43
|
Posts: 3,319 |
Thanked: 5,610 times |
Joined on Aug 2008
@ Finland
|
#238
|
|
2010-03-24
, 23:12
|
Posts: 1,341 |
Thanked: 708 times |
Joined on Feb 2010
|
#239
|
|
2010-03-24
, 23:38
|
Posts: 3,319 |
Thanked: 5,610 times |
Joined on Aug 2008
@ Finland
|
#240
|
Or, then again, Debian could make a world a favour and change to RPM-system so in LSB-RPM modern features could be added not worrying alien won't support them.
Tags |
rabble-rousing, rpm vs. deb war, rpmligion vs debligion, vote attila77 |
|
- It all started when the move to Fedora/RPM was announced (cue ranting),
- After much discussion the fact that RPM is feature par with DEB started to settle down,
- So then came more ranting about Fedora not doing as much ARM work as Debian [dubious statement][discuss].
- Then someone correctly pointed that MeeGo was not actually based on Fedora,
- And as such the thread became about how bad it was that MeeGo was not being based in any existing distro (like Debian) [sigh].
By now, who knows what the thread is about, other than complaining that MeeGo is not based on Debian . Maybe a link to the Debian Mobile distro in the works would work?