MITM attacks against portsnap and freebsd-update

Chris H bsd-lists at
Fri Apr 11 13:31:10 UTC 2014

> Quoting David Noel <david.i.noel at>:
>> 4. Retire portsnap.
>> Details
> [snip]
>> Retiring Portsnap
>> With the inclusion of svnlite in 10 I think the valid question comes
>> up as to whether we really need the portsnap system or whether it
>> could be safely retired.
> I see in the PR you suggest getting rid of the portsnap servers as
> well. 8 and 9 are still supported releases. Does this mean that anyone
> running 8.4 or 9.2 is going to lose the ability to upgrade their ports
> tree quickly and easily unless they also upgrade their servers /from a
> supported release/?

I had intended to comment on this, as well.
I also take issue with the (seemingly) premature demise of pkg_ in this regard.


> _______________________________________________
> freebsd-hackers at mailing list
> To unsubscribe, send any mail to "freebsd-hackers-unsubscribe at"

More information about the freebsd-questions mailing list