Re: trusting .deb packages

2018-07-25 Thread Brian
On Thu 26 Jul 2018 at 01:30:09 +1000, Andrew McGlashan wrote: > On 25/07/18 23:52, Darac Marjal wrote: > >> I'm not sure you understand how Debian works, then. Debian is a > >> political animal as much as it is technical. There was a > >> technical requirement for a better init system, so there w

Re: trusting .deb packages

2018-07-25 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 25/07/18 23:52, Darac Marjal wrote: >> I'm not sure you understand how Debian works, then. Debian is a >> political animal as much as it is technical. There was a >> technical requirement for a better init system, so there was a >> political pr

Re: trusting .deb packages

2018-07-25 Thread Darac Marjal
On Wed, Jul 25, 2018 at 03:54:11PM +1000, Andrew McGlashan wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, On 25/07/18 07:41, Matthew Crews wrote: In addition to this, be sure not to break Debian: https://wiki.debian.org/DontBreakDebian https://wiki.debian.org/DebianSoftware#Footno

Re: trusting .deb packages

2018-07-25 Thread john doe
On 7/25/2018 7:40 AM, Andrew McGlashan wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 25/07/18 04:31, john doe wrote: Also verifying signature using gnupg and checksum is a must (sha512). Such verification is suspect, anyone can create gpg keys for anyone (so trust in the keys us

Re: trusting .deb packages

2018-07-24 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, On 25/07/18 07:41, Matthew Crews wrote: > In addition to this, be sure not to break Debian: > > https://wiki.debian.org/DontBreakDebian > https://wiki.debian.org/DebianSoftware#Footnotes "Broken" many of us strongly believe that once the

Re: trusting .deb packages

2018-07-24 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 25/07/18 12:17, Rick Thomas wrote: > On Jul 24, 2018, at 2:41 PM, Matthew Crews > wrote: >> Personally, I have a low degree of trust for Mega.nz, so caveat >> emptor. > Why do you say that? (serious question!) Have there been reports > of pro

Re: trusting .deb packages

2018-07-24 Thread Andrew McGlashan
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 25/07/18 04:31, john doe wrote: > Also verifying signature using gnupg and checksum is a must > (sha512). Such verification is suspect, anyone can create gpg keys for anyone (so trust in the keys used is essential, but more difficult to attain)

Re: trusting .deb packages

2018-07-24 Thread Ben Caradoc-Davies
On 25/07/18 14:35, Matthew Crews wrote: On 7/24/18 7:17 PM, Rick Thomas wrote: On Jul 24, 2018, at 2:41 PM, Matthew Crews wrote: Personally, I have a low degree of trust for Mega.nz, so caveat emptor. Why do you say that? (serious question!) Have there been reports of problems? A few reaso

Re: trusting .deb packages

2018-07-24 Thread Gene Heskett
On Tuesday 24 July 2018 22:35:17 Matthew Crews wrote: > On 7/24/18 7:17 PM, Rick Thomas wrote: > > On Jul 24, 2018, at 2:41 PM, Matthew Crews wrote: > >> Personally, I have a low degree of trust for Mega.nz, so caveat > >> emptor. > > > > Why do you say that? (serious question!) Have there bee

Re: trusting .deb packages

2018-07-24 Thread Matthew Crews
On 7/24/18 7:17 PM, Rick Thomas wrote: > > On Jul 24, 2018, at 2:41 PM, Matthew Crews wrote: > >> Personally, I have a low degree of trust for Mega.nz, so caveat emptor. > > Why do you say that? (serious question!) Have there been reports of > problems? > > Enjoy! > Rick > A few reasons:

Re: trusting .deb packages

2018-07-24 Thread Rick Thomas
On Jul 24, 2018, at 2:41 PM, Matthew Crews wrote: > Personally, I have a low degree of trust for Mega.nz, so caveat emptor. Why do you say that? (serious question!) Have there been reports of problems? Enjoy! Rick

Re: trusting .deb packages

2018-07-24 Thread Ben Caradoc-Davies
On 25/07/18 13:04, Anil Duggirala wrote: Also consider using the open-source megatools package. 1.10.0 has just been released and is expected in Debian soon. megatools 1.10.0 has just been accepted into unstable and is in the build queue. I did make a search and found this package, an older ver

Re: trusting .deb packages

2018-07-24 Thread Anil Duggirala
> > Also consider using the open-source megatools package. 1.10.0 has just > > been released and is expected in Debian soon. > > megatools 1.10.0 has just been accepted into unstable and is in the > build queue. > I did make a search and found this package, an older version 1.9.98-1 which see

Re: trusting .deb packages

2018-07-24 Thread Ben Caradoc-Davies
On 25/07/18 09:51, Ben Caradoc-Davies wrote: On 25/07/18 03:45, Anil Duggirala wrote: I am thinking about installing the Mega.nz app on my Debian Stretch installation. They provide a .deb package. Is there anything I can do to ensure this is a safe package? To know that this package will not c

Re: trusting .deb packages

2018-07-24 Thread Ben Caradoc-Davies
On 25/07/18 03:45, Anil Duggirala wrote: I am thinking about installing the Mega.nz app on my Debian Stretch installation. They provide a .deb package. Is there anything I can do to ensure this is a safe package? To know that this package will not create a security vulnerability on my system?

Re: trusting .deb packages

2018-07-24 Thread Matthew Crews
‐‐‐ Original Message ‐‐‐ On July 24, 2018 9:43 AM, Dan Ritter wrote: > On Tue, Jul 24, 2018 at 10:45:38AM -0500, Anil Duggirala wrote: > > > I am thinking about installing the Mega.nz app on my Debian Stretch > > installation. They provide a .deb package. Is there anything I can do to

Re: trusting .deb packages

2018-07-24 Thread john doe
On 7/24/2018 6:43 PM, Dan Ritter wrote: On Tue, Jul 24, 2018 at 10:45:38AM -0500, Anil Duggirala wrote: I am thinking about installing the Mega.nz app on my Debian Stretch installation. They provide a .deb package. Is there anything I can do to ensure this is a safe package? To know that this

Re: trusting .deb packages

2018-07-24 Thread Anil Duggirala
Thanks Dan, your questions answer my question. In this case they do provide the source code, which am not competent enough to understand, but I do trust them. thanks a lot,

Re: trusting .deb packages

2018-07-24 Thread Dan Ritter
On Tue, Jul 24, 2018 at 10:45:38AM -0500, Anil Duggirala wrote: > I am thinking about installing the Mega.nz app on my Debian Stretch > installation. They provide a .deb package. Is there anything I can do to > ensure this is a safe package? To know that this package will not create a > security