Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-08 Thread Zac Medico
On 03/08/2015 08:02 AM, Mark Kubacki wrote: On 03/06/2015 09:50 AM, Mark Kubacki wrote: And by default you cannot compare the result with any authoritative source. 2015-03-08 0:26 GMT+01:00 Zac Medico zmed...@gentoo.org: Ideally, we can rely on security mechanisms built into git [1],

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-08 Thread Zac Medico
On 03/08/2015 07:59 AM, Patrick Schleizer wrote: Zac Medico: On 03/06/2015 09:50 AM, Mark Kubacki wrote: We're on the same side here. Do we have numbers showing the ratio portage used with defaults vs. where [webrsync-gpg] is described in many hardening guides for gentoo and widely used

Re: [gentoo-portage-dev] Security and Comparison of Portage with other Package Managers

2015-03-08 Thread Patrick Schleizer
Zac Medico: On 03/06/2015 09:50 AM, Mark Kubacki wrote: We're on the same side here. Do we have numbers showing the ratio portage used with defaults vs. where [webrsync-gpg] is described in many hardening guides for gentoo and widely used among the security conscious applies? DNS not being