Red Hat, Fedora Servers Compromised 278
An anonymous reader writes "In an email sent to the fedora-announce mailing list, it has been revealed that both Fedora and Red Hat servers have been compromised. As a result Fedora is changing their package signing key. Red Hat has released a security advisory and a script to detect potentially compromised openssh packages."
Do they run linux? (Score:5, Funny)
damn't (Score:2, Funny)
source code filching! nothing else.
Re:OpenSSH bug? (Score:3, Funny)
In keeping with the spirit of /., I didn't read TFA.
However, I'd say this is totally unrelated to the Debian bug. The Debian bug was caused as a result of a change a Debian package maintainer made. Since he only made the change for the Debian package and didn't push it back upstream, it's highly unlikely that they are related.
Re:Do they run linux? (Score:5, Funny)
Suuure... (Score:2, Funny)
"Just run this shell script to verify you're not infected"
No way I'm falling for that one.
Back to work.
Re:roughly 30 kernel 0dayz circulating (Score:1, Funny)
I can confirm that Jesus falcon punched Obama until he gave up the secret 30 government 0-days in the kernel.
Re:Nothing to see here. (Score:3, Funny)
Yea I guess they don't care that a kernel compromise completely negates any security benefit from SELinux.
Re:Do they run linux? (Score:0, Funny)
Your both wrong. Linux in general has a much better security record and problems tend to be fixed much quicker aswell (plus microsoft have a history of just denying blatant security holes).
Also linux *IS* an operating system. It does not in any way rely on windows and most certainly does not run *ON* windows. It is completely seperate to windows and will run on computers even if they have never had windows on them.
Re:Do they run linux? (Score:4, Funny)
***Whoosh***
Re:roughly 30 kernel 0dayz circulating (Score:3, Funny)
Nice. I just compiled 2.6.27-rc4 on my notebook so I guess I'm safe for now. ;)
Re:Do they run linux? (Score:4, Funny)
Re:Do they run linux? (Score:2, Funny)
Yeah, but this is as bad as striking out at a tee-ball game.
Re:Do they run linux? (Score:1, Funny)
Re:Nothing to see here. (Score:4, Funny)
Our code signing machine is locked in a cage and powered up only for purposes of code signing. Executables to be signed are written to a previously wiped USB drive which is attached to the signing machine only when packages are to be signed. The signing machine has not been connected to a network since before the keys were generated. The private key only exists on that machine and in a single separately encrypted backup.
Meh!
Well my code signing machine is more secure. We don't put USB sticks directly into the signing machine. We copy the package to a USB stick and then to the 'transfer' machine. The code signing machine is then 'connected' to the transfer machine by infared link which is unblocked by lifting a large steel slab out of the way. The transfer happens via zmodem, and it scanned on both the transfer machine and the code signing machine. Finally we sign the package and transfer it back just before the poor intern's strength gives out and the steel slab slams back down, killing the connection and the intern...(just in case he saw me type in the 42-character passphrase to the private key).
Beat that security...
Re:Nothing to see here. (Score:3, Funny)