K.S. Bhaskar on 2 Jul 2021

[PLUG] Major Linux RPM problem uncovered

I stumbled onto https://www.zdnet.com/article/major-linux-rpm-problem-uncovered/ this morning. I presume (hope?) this is not an issue if one is only installing from legitimate repositories as presumably the user validation they are doing when accepting commits provides an additional layer of defense. Using an appropriately encrypted and validated connection to the repositories should protect against attacks that divert the DNS or network routes to a bogus repository.

Thoughts welcome. Thanks.

– Bhaskar
