Live data from Hacker News

Security Incident on FreeBSD Infrastructure

freebsd.org

31–37 of 37 posts

Re: Security Incident on FreeBSD Infrastructure

#31
I have a couple of FreeBSD machines which pulled binary packages between those dates. I'm not overly worried. The packages have been removed and installed again from ports after a fresh portsnap dump and the systems have been verified with "freebsd-update IDS" against known good signatures. Any modified files were manually checked. I use MAC on each machine and pf up front on firewalls so I know what is going in and out as well.

The fact that these mechanisms are available is the reason I use such a system.

Also, if you consider any problems like this happening to a closed source vendor, you may never know it's happened. And don't tell me they don't do it as I've worked for a couple of companies that felt that burying security fuck ups was acceptable practice. It's why I don't work for them any more.

Re: Security Incident on FreeBSD Infrastructure

#32
post #31

I have a couple of FreeBSD machines which pulled binary packages between those dates. I'm not overly worried. The packages have been removed and installed again from ports after a fresh portsnap dump and the systems have been verified with "freebsd-update IDS" against known good signatures. Any modified files were manually checked. I use MAC on each machine and pf up front on firewalls so I know what is going in and…

Actually, even with opensource you may never know it happened. Does not matter where it comes from:

- They have to find it out first.

- Then they've to be willing to disclose the incident

- Even if, you still trust the source of the packages, the developers, etc. There's a zillion bugs that look like "just an error" which can also be "just a backdoor".

For these reasons, running mac, checking modified files, etc is ALWAYS good practice (that you seem to follow, don't get me wrong - but that's pretty rare)

Re: Security Incident on FreeBSD Infrastructure

#33
post #32
post #31

I have a couple of FreeBSD machines which pulled binary packages between those dates. I'm not overly worried. The packages have been removed and installed again from ports after a fresh portsnap dump and the systems have been verified with "freebsd-update IDS" against known good signatures. Any modified files were manually checked. I use MAC on each machine and pf up front on firewalls so I know what is going in and…

Actually, even with opensource you may never know it happened. Does not matter where it comes from: - They have to find it out first. - Then they've to be willing to disclose the incident - Even if, you still trust the source of the packages, the developers, etc. There's a zillion bugs that look like "just an error" which can also be "just a backdoor". For these reasons, running mac, checking modified files, etc is A…

I only follow them after I got owned in '97 on the end of a dialup for running an open telnet server (on FreeBSD) with a crappy root password :)

Re: Security Incident on FreeBSD Infrastructure

#37
post #33
post #32

Earlier quoted context omitted.

Actually, even with opensource you may never know it happened. Does not matter where it comes from: - They have to find it out first. - Then they've to be willing to disclose the incident - Even if, you still trust the source of the packages, the developers, etc. There's a zillion bugs that look like "just an error" which can also be "just a backdoor". For these reasons, running mac, checking modified files, etc is A…

I only follow them after I got owned in '97 on the end of a dialup for running an open telnet server (on FreeBSD) with a crappy root password :)

Nobody takes security seriously until they've learned to distrust a computer they know intimately. It's a fact of life.
Post reply on HN