LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-08-2013, 04:30 PM   #1
displace
Member
 
Registered: Jan 2013
Location: EU
Distribution: Debian
Posts: 268

Rep: Reputation: 25
Repository resilience against governments


Sorry, I'm a bit paranoid with all this NSA scandal.

Recently I've come across a news article where it is described how the FBI tried to hunt down a computer in an unknown location and its owner. The article goes on how they tried to compromise the users PC by posting a link in his yahoo email account to a server controlled by feds that's serving malicious code. While I'm guessing this user was using windows on his laptop, I can't stop asking myself how would a government agency like NSA, FBI, DoD, etc try to compromise a linux machine. So I was wondering... besides the obvious ways of tricking a user to download a malicious component, what's the chance that a repository gets hit by a national security letter or an equivalent?

I mean can the software downloaded from official repositories really be trusted? What's the chance a goventment orders a company like Canonical or maybe an admin of the Arch linux repository to upload and serve an OS update with an infected component to some of its users? Since the component would be signed by the admin's private key, the OS would simply install it without question. How can such an intrusion into a repository be detected? Can a government even force a repository admin to upload malware.. and sign it with his private key?


Please keep the conversation constructive, I'm asking this question for the purpose of learning more about linux security landscape.
 
Old 12-08-2013, 06:24 PM   #2
k3lt01
Senior Member
 
Registered: Feb 2011
Location: Australia
Distribution: Debian Wheezy, Jessie, Sid/Experimental, playing with LFS.
Posts: 2,900

Rep: Reputation: 637Reputation: 637Reputation: 637Reputation: 637Reputation: 637Reputation: 637
A government, as we have found out and history shows us time and again, can do whatever it wants. The important thing is not the government rather the important thing is the people. Are the people, or corporations, trustworthy and do they have their users as their highest priority. If the answer is yes then you'll be ok, if the answer is no then choose a distro that does.
 
1 members found this post helpful.
Old 12-08-2013, 11:43 PM   #3
Lantzvillian
Member
 
Registered: Oct 2007
Location: BC, Canada
Distribution: Fedora, Debian
Posts: 210

Rep: Reputation: 41
Depends on how thick a person wants to make a hat out of tinfoil I guess. One could say that that repositories might not really be the worst offender - if I was the government I would affect things like actual algorithms used for encryption, hashing and of course I'd probably go after the hardware itself.

Ultimately, a user can choose to be extremely paranoid and cause themselves harm or be cautious and go with a distribution that chooses the user first (which still excludes the actual code authors and contributors).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Netflix open sources Hystrix resilience library LXer Syndicated Linux News 0 11-27-2012 11:42 PM
How to test driver resilience with down_interruptible( )? nickolais Linux - Software 0 04-17-2009 03:10 PM
LXer: Open source for governments LXer Syndicated Linux News 0 12-20-2005 09:31 PM
Governments which have chosen opensource newpenguin General 1 10-02-2003 06:49 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:56 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration