Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-08 Thread Patrick Schleizer
Zac Medico: On 03/06/2015 09:50 AM, Mark Kubacki wrote: We're on the same side here. Do we have numbers showing the ratio portage used with defaults vs. where [webrsync-gpg] is described in many hardening guides for gentoo and widely used among the security conscious applies? DNS not being

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-06 Thread Patrick Schleizer
Hi, it was naive of me to attempt to create such a comparison table. Takes much more time than I have available for this. It was to be expected that there are disagreements and I cannot resolve them without checking the code myself and perhaps without coming up with proof of concept exploitation

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-05 Thread Patrick Schleizer
I used the footnote numbers to reference the attacks. I am afraid, this might cause some confusion. The numbers you have used won't stay stable. Those were autogenerated numbers of footnotes. As footnotes change, these numbers change. To keep your post understandable, I created a snapshot before

[gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-05 Thread Patrick Schleizer
Hi, I am currently working on a comparison of package managers in which Portage is part of. https://www.whonix.org/wiki/Comparison_Of_Package_Managers Would you be interested to check if the current assessments are correct and/or to fill the remaining gaps? Where the comparison table is hosted