Open main menu

Linux and Unix Users Group at Virginia Teck Wiki β

Changes

Arch

96 bytes removed, 01:54, 6 February 2012
Criticism
== Criticism ==
Until Pacman 4, Arch does did not currently support package signing.[https://bugs.archlinux.org/task/5331] . As a result of this, an insecure mirror (including any mirrors upstream of the one you are synching from) or a untrusted connection (such as a man in the middle attack between you and the mirror, or any hops between mirrors) could result in your system's security being compromised. There has been some work towards adding package signing functionality to Arch[http://projects.archlinux.org/users/allan/pacman.git/log/?h=gpg], however there have been claims that the developers are not concerned with the security implications and are reluctant to accept improvements from outside of the core team[http://igurublog.wordpress.com/2011/02/19/archs-dirty-little-notso-secret/]. Package signing is on the roadmap for Pacman 3.6.X[https://wiki.archlinux.org/index.php/Pacman_Roadmap]
[[Category:Linux distributions]]
[[Category:Round 2 migration]]
Anonymous user