Security Incident on FreeBSD Infrastructure
freebsd.org
Security Incident on FreeBSD Infrastructure
1–10 of 37 posts
Re: Security Incident on FreeBSD Infrastructure
#2FreeBSD reports are always extremely professional, I love it.
Re: Security Incident on FreeBSD Infrastructure
#3Interesting choice that some machines will not be reinstalled, only "thoroughly audited".
Re: Security Incident on FreeBSD Infrastructure
#4Interesting choice that some machines will not be reinstalled, only "thoroughly audited".
There are some systems (generally speaking, ones which were installed in the past few weeks) for which we know exactly what files should be installed and what their SHA256 hashes are. Thoroughly audited means "every single bit is correct".
Re: Security Incident on FreeBSD Infrastructure
#5Interesting choice that some machines will not be reinstalled, only "thoroughly audited".
I'm surprised they weren't more transparent about that reasoning... maybe those machines were running everything within jails?
Re: Security Incident on FreeBSD Infrastructure
#6They use SVN still?
Re: Security Incident on FreeBSD Infrastructure
#7They use SVN still?
FreeBSD only finished switching from CVS to SVN for the core repositories a few months ago. (And there's still some legacy systems which rely on CVS.)
Re: Security Incident on FreeBSD Infrastructure
#8This is how you tell people about a security breach. Inform them soon as you know with what you know and assume the worst with your appraoch to restoring things.
Much respect and defineing the word professional for many.
Re: Security Incident on FreeBSD Infrastructure
#9They use SVN still?
Re: Security Incident on FreeBSD Infrastructure
#10Interesting choice that some machines will not be reinstalled, only "thoroughly audited".
They're probably one of the few projects with such a track record that we can take them at their word. Thoroughly audited will mean exactly that.
They're most definitely not amateurs, see the back catalogue for examples of 'how to do it right'