MITM attacks against portsnap and freebsd-update

Chris H bsd-lists at bsdforge.com
Fri Apr 11 13:31:10 UTC 2014


> Quoting David Noel <david.i.noel at gmail.com>:
>
>> 4. Retire portsnap.
>>
>> Details
> [snip]
>> Retiring Portsnap
>>
>> With the inclusion of svnlite in 10 I think the valid question comes
>> up as to whether we really need the portsnap system or whether it
>> could be safely retired.
>
> I see in the PR you suggest getting rid of the portsnap servers as
> well. 8 and 9 are still supported releases. Does this mean that anyone
> running 8.4 or 9.2 is going to lose the ability to upgrade their ports
> tree quickly and easily unless they also upgrade their servers /from a
> supported release/?

I had intended to comment on this, as well.
I also take issue with the (seemingly) premature demise of pkg_ in this regard.

--Chris

>
> _______________________________________________
> freebsd-hackers at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
> To unsubscribe, send any mail to "freebsd-hackers-unsubscribe at freebsd.org"
>



More information about the freebsd-questions mailing list