看板FB_security
標 題Re: Retiring portsnap [was MITM attacks against portsnap and
發信站NCTU CS FreeBSD Server (Mon Apr 14 00:07:09 2014)
轉信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
> Portsnap uses secured access for getting updates out of Subversion
The portsnap open source project pulls data insecurely using the url
svn://svn.freebsd.org.
The server-side code of the FreeBSD portsnap system -- a closed source
fork of the open source portsnap project -- happens to use secured
access for pulling data from svn. This is not a trivial point.
> whereas doing "svn co" remotely generally does not.
Without knowing usage statistics there is no way to describe a
"general" use case for `svn co`. The security of access of that
command is entirely dependent on how it is parameterized.
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"