On Du, 20 nov 11, 18:10:34, Camaleón wrote:
> 
> I've never faced a security problem when installing over the network 

How can you tell? ;)

> (Internet) and take no additional countermeasures but ensuring the net 
> ISO checksum for the image I have downloaded is okay.
> 
> A compromised mirror can hit at anytime not just when installing.

A compromised mirror would be the least of my worries (due to 
secure-apt). In theory it could be possible to compromise the system 
during the install, but I think the risk is quite low.

It would probably have to be a targeted attack during a narrow window of 
a non-standard system not listening to any ports (unless you 
specifically activated ssh, but then you should know what you're doing).

Regards,
Andrei
-- 
Offtopic discussions among Debian users and developers:
http://lists.alioth.debian.org/mailman/listinfo/d-community-offtopic

Attachment: signature.asc
Description: Digital signature

Reply via email to