From: Florian Philipp <lists@binarywings.net>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Re: Which desktop antivirus?
Date: Sun, 23 Oct 2011 11:06:35 +0200 [thread overview]
Message-ID: <4EA3D91B.2060006@binarywings.net> (raw)
In-Reply-To: <201110230849.53603.michaelkintzios@gmail.com>
[-- Attachment #1: Type: text/plain, Size: 1918 bytes --]
Am 23.10.2011 09:49, schrieb Mick:
> On Saturday 22 Oct 2011 22:30:45 Volker Armin Hemmann wrote:
>> Am Samstag 22 Oktober 2011, 18:14:32 schrieb Nikos Chantziaras:
>>> On 10/22/2011 05:07 PM, Adam Carter wrote:
>>>>> there aren't any Linux viruses,
>>>>
>>>> Except for the ones listed on the page below, which is probably
>>>> incomplete. http://en.wikipedia.org/wiki/Linux_malware
>>>>
>>>> But yeah, on a linux desktop (especially a Gentoo one) you don't need
>>>> a virus scanner. Yet.
>>>
>>> There are literally *millions* of Windows viruses. The Wikipedia page
>>> just proves Linux has virtually no viruses, and those listed don't even
>>> work anymore (exploits have been patched long ago.) Most existing Linux
>>> malware targets servers (like PHP software exploits in forums, wikis,
>>> etc) and desktop users don't need to worry.
>>>
>>> Furthermore, even if there were enough Linux viruses to worry about,
>>> there isn't a good way of getting infected. On Windows, you download
>>> random executables from the net. On Gentoo, you install your stuff
>>> through portage. It's nearly impossible to get infected.
>>
>> except when someone puts up or takes over a rsync server and starts
>> providing malicious ebuilds.
>>
>>
>> Hilarious.
>
> Isn't that what happened back in 2003/04? I can't recall exactly but there
> was some discussion where it was suggested that clients should rsync against
> two different mirrors and diff the portage contents (or hashes thereof?), before
> accepting the sync result.
That still doesn't protect you against man-in-the-middle attacks or an
attack against the CVS tree (like the recent kernel.org disaster).
Signing the manifest files is really the only reasonable solution. Good
thing there seems to be some progress in that direction:
https://bugs.gentoo.org/show_bug.cgi?id=360363
Regards,
Florian Philipp
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 262 bytes --]
next prev parent reply other threads:[~2011-10-23 9:08 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-10-22 11:27 [gentoo-user] Which desktop antivirus? Mick
2011-10-22 11:29 ` Nilesh Govindarajan
2011-10-22 11:43 ` Florian Philipp
2011-10-22 14:22 ` Jonas de Buhr
2011-10-22 15:40 ` Mick
2011-10-22 17:03 ` [gentoo-user] " Nikos Chantziaras
2011-10-22 20:31 ` Neil Bothwick
2011-10-30 12:35 ` Mick
2011-10-22 11:37 ` Nikos Chantziaras
2011-10-22 14:07 ` Adam Carter
2011-10-22 14:22 ` Pandu Poluan
2011-10-22 15:14 ` Nikos Chantziaras
2011-10-22 19:55 ` Mark Knecht
2011-10-22 20:47 ` Florian Philipp
2011-10-22 21:30 ` Volker Armin Hemmann
2011-10-23 4:04 ` Adam Carter
2011-10-23 7:49 ` Mick
2011-10-23 9:06 ` Florian Philipp [this message]
2011-10-22 17:27 ` [gentoo-user] " Dale
2011-10-22 18:46 ` Mick
2011-10-22 19:15 ` Dale
2011-10-23 11:01 ` Volker Armin Hemmann
2011-10-29 15:39 ` Mick
2011-10-29 17:26 ` Mark Knecht
2011-10-29 18:11 ` Mick
2011-10-29 18:25 ` Pandu Poluan
2011-10-29 18:40 ` Mick
2011-10-30 12:50 ` Mick
2011-10-30 13:32 ` James Broadhead
2011-10-30 15:29 ` Mick
2011-10-31 9:54 ` James Broadhead
2011-10-30 20:01 ` James Broadhead
2011-10-23 22:47 ` Dale
2011-10-22 19:05 ` Andrey Moshbear
2011-10-22 19:17 ` Pandu Poluan
2011-10-23 7:20 ` du yang
2011-10-23 8:38 ` Pandu Poluan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4EA3D91B.2060006@binarywings.net \
--to=lists@binarywings.net \
--cc=gentoo-user@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox