On Wed, 2007-20-06 at 00:47 -0400, Mike Frysinger wrote:
> there are many files out there that contain critical information about your 
> system ... 

> however, there are certainly cases where the admin fully knows what they're 
> doing and they want to create a binary package of their system with these 
> sensitive files ... so where to meet in the middle.

> any other potential ideas ?  (pretend my idea here isnt the greatest thing 
> since Robot Chicken)

I will claim that almost any file in /etc is potentially sensitive (even
if it does not contain passwords, if may contain other informations
interesting to a cracker). And even if we did what you propose, we'd run
the risk of missing some and giving the user a false sense of security.

Maybe we should document somewhere that the only way to make bin pkg
that are safe for public distribution is to do emerge -b or -B .. And
that pkgs built with quickpkg may contain sensitive information.

-- 
Olivier Crête
[EMAIL PROTECTED]
Gentoo Developer

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to