Bug#678950: screen: secure instructions in the most recent NEWS.Debian entry

2012-06-25 Thread Christoph Anton Mitterer
Package: screen Version: 4.1.0~20120320gitdb59704-4 Severity: normal Tags: security Hi. In the most recent NEWS.Debian entry, you describe how users can retrieve an old version of the screen package in order to connect to pre 4.1 sesssions. A security problem IMHO is, that a simple download,

Bug#678950: screen: secure instructions in the most recent NEWS.Debian entry

2012-06-25 Thread Axel Beckert
Hi Christoph, Christoph Anton Mitterer wrote: In the most recent NEWS.Debian entry, you describe how users can retrieve an old version of the screen package in order to connect to pre 4.1 sesssions. A security problem IMHO is, that a simple download, not even https secured (which also

Bug#678950: screen: secure instructions in the most recent NEWS.Debian entry

2012-06-25 Thread Christoph Anton Mitterer
On Mon, 2012-06-25 at 14:05 +0200, Axel Beckert wrote: HTTPS may not be supported by all mirrors returned by cdn.debian.net. Additionally for APT via HTTPS to work, a separate package (apt-transport-https) is needed which may not be installed. See also below. Yeah,... and more over,... we

Bug#678950: screen: secure instructions in the most recent NEWS.Debian entry

2012-06-25 Thread Axel Beckert
Hi, Christoph Anton Mitterer wrote: I consciously avoid APT and dpkg at that point as the howto must work even when the dpkg or APT state databases are locked by a process running inside the currently not reachable screen session. Valid point, too. Does dpkg-deb work without locking?

Bug#678950: screen: secure instructions in the most recent NEWS.Debian entry

2012-06-25 Thread Christoph Anton Mitterer
Hey. On Mon, 2012-06-25 at 19:35 +0200, Axel Beckert wrote: Right. But after wheezy the whole stuff will likely be removed from the package anyway upgrades from Oldstable to Stable+1 are not supported. Of course,... I just wondered whether they can go away during wheezy? Well if someone