Bug#413070: notes on security

2009-09-06 Thread Jari Aalto
Christoph Anton Mitterer writes: >> ... sources are fetched from Bazaar version control >> repository hosted by launchpad.net. The repository's integrity isn't >> compromized while the cloning, the download, happends. > > I mean regardless of whether you download a tgz or something from VCS,... >

Bug#413070: notes on security

2009-09-06 Thread Christoph Anton Mitterer
Quoting Jari Aalto : I think you refer to tar.gz etc. sources that are available from Web pages. In this case the sources are fetched from Bazaar version control repository hosted by launchpad.net. The repository's integrity isn't compromized while the cloning, the download, happends. If you hav

Bug#413070: notes on security

2009-09-06 Thread Jari Aalto
> Philipp Hübner writes: >The newest version of truecrypt is 6.0a which uses fuse and runs >completely in userspace. > >What about this? I'd imagine that users would prefer the up2date version. - 4.3 is stable and has no problems (5.x and 6.x there are multiple reports) - 4.3 is faster and more

Bug#413070: notes on security

2009-09-05 Thread Christoph Anton Mitterer
Hi. May I suggest in advance: If you download stuff from the web (e.g. the truecrypt sources) that get somhow installed,.. you really should add some hashsums checking (SHA512) and abort package installation (or creation) if the sums don't match with the ones shipped with your package (and