خرید بک لینک

Thread moved to Security as the more appropriate forum.

Approved mirror sites do undertake to hash check all files that they mirror, but in the end, all you've got is their word on this. Your upgrade downloads are also hash checked as part of the upgrade process itself, but only with the mirror file. If a bad guy changes a file in the mirror, there is no way for the average bear to know. You are right to note this as a security risk. Gurus could hash check against the original files in the master repository I suppose, but I don't know how to do this and have never felt the need.

As with all distributed models of software provisioning, it's based on a chain of trust. And as with all chains, this one is only as strong as its weakest link. In order to qualify as an official mirror site, mirrors have to meet some Ubuntu standards. I don't know the process by which Canonical oversees or enforces those standards.

It is theoretically possible for a rogue insider to change a mirror file. Many papers have been written about this vulnerability. I don't know of any real world occurrence in Ubuntu of such an exploit.

Unfortunately, security is not amenable to binary solutions. It is invariably comprised of shades of grey. At some point, we are forced to trust somebody, else we won't be able to get anything done. However, your instincts are good to question these matters.

برچسب: نویسنده: استخدام کار تاريخ: يکشنبه 19 ارديبهشت 1395 ساعت: 0:25

صفحه بندی