MITM attacks against portsnap and freebsd-update

J.McKeown at ru.ac.za J.McKeown at ru.ac.za
Fri Apr 11 07:46:28 UTC 2014


Quoting David Noel <david.i.noel at gmail.com>:

> 4. Retire portsnap.
>
> Details
[snip]
> Retiring Portsnap
>
> With the inclusion of svnlite in 10 I think the valid question comes
> up as to whether we really need the portsnap system or whether it
> could be safely retired.

I see in the PR you suggest getting rid of the portsnap servers as  
well. 8 and 9 are still supported releases. Does this mean that anyone  
running 8.4 or 9.2 is going to lose the ability to upgrade their ports  
tree quickly and easily unless they also upgrade their servers /from a  
supported release/?



More information about the freebsd-hackers mailing list