16 ms·
So the only thing the NSA has to do is hack/convince/rendition/break-into-house a single person who holds a package signing key, and then they can MITM your pac
by computer 13y ago
So the only thing the NSA has to do is hack/convince/rendition/break-into-house a single person who holds a package signing key, and then they can MITM your pacman updater and have you as well.
And there's enough people with such a key to choose from: https://www.archlinux.org/master-keys/ https://www.archlinux.org/master-keys/.
(I run Arch as well, but I have no such illusions of security.)
- Fuxy 13y agoAs i said not impossible but at least we're not giving the NSA information about vulnerabilities months in advance of us fixing it. Where there's a will there's a way especially if you have billions of dollars in funding and the freedom to do so i just aim to make it as difficult as possible.
- clarry 13y agoIs running Linux all you can do to make it as difficult as possible?
- Fuxy 13y agoNo obviously not. There's a lot of things you can do to protect you privacy but it all starts with a good choice of OS and hardware. If the foundation is compromised there's no point in anything else you do to protect your privacy. Edit: Yes Arch it's not particularly security conscious I choose to compromise some security to stay on the bleeding edge now that could mean that I get some bad code sometimes but that also means that it gets fixed sooner too. Having a rolling release system that you can mold to your needs is worth it for me.
- clarry 13y agoI'm not trying to bash Arch, but it never looked like a particularly security-conscious or focused distro. To me it looked like it's about being cool and bleeding edge and Gentoo with binary packages... and I have a faint recollection of seeing some rather unimpressive packaging, though that was long time ago. So it runs on i686 and amd64 only. How do you select "good" hardware?
- Fuxy 13y agoIn an ideal world it would be open source hardware where you can review anything from the circuit diagram to the firmware. However since there's no such thing you will have to choose who you trust.
- danieldk 13y agoOr just employ people to contribute to some of the many popular upstream projects to slip in a vulnerability or two. Edit: not to discredit Linux of FLOSS, at least there is the possibility to analyse the source code.