Bug#558784: Isn't this a security problem?

2010-06-28 Thread David Kalnischkies
2010/6/23 Goswin von Brederlow goswin-...@web.de: That would complicate things when using deb [keyring=debian-lenny.gpg] http://ftp.debian.org/debian stable main The idea of specifying a specific keyring is so that one compromised key will not endanger all sources.list entries to attacks.

Bug#558784: Isn't this a security problem?

2010-06-23 Thread Goswin von Brederlow
David Kalnischkies kalnischkies+deb...@gmail.com writes: 2010/6/12 Torsten Landschoff t.landsch...@gmx.net: I would consider this to be a critical issue as it could become a security problem. Let's assume an archive key is compromised. As an admin reading this on some information channel

Bug#558784: Isn't this a security problem?

2010-06-14 Thread David Kalnischkies
2010/6/12 Torsten Landschoff t.landsch...@gmx.net: I would consider this to be a critical issue as it could become a security problem. Let's assume an archive key is compromised. As an admin reading this on some information channel (irc, twitter, lwn.net, whatever) I would just remove the

Bug#558784: Isn't this a security problem?

2010-06-11 Thread Torsten Landschoff
I would consider this to be a critical issue as it could become a security problem. Let's assume an archive key is compromised. As an admin reading this on some information channel (irc, twitter, lwn.net, whatever) I would just remove the key as shown by Tollef. Only by reading this bug report I