Welcome Guest.   Make a donation to an author on the site June 19, 2013, 06:46:31 AM  *

Please login or register.
Or did you miss your validation email?


Login with username and password (forgot your password?)
Why not become a lifetime supporting member of the site with a one-time donation of any amount? Your donation entitles you to a ton of additional benefits, including access to exclusive discounts and downloads, the ability to enter monthly free software drawings, and a single non-expiring license key for all of our programs.


You must sign up here before you can post and access some areas of the site. Registration is totally free and confidential.
 
Free DonationCoder.com Member Kit: Submit Request.
   
   Forum Home   Thread Marks Chat! Downloads Search Login Register  
Pages: [1]   Go Down
  Reply  |  New Topic  |  Print  
Author Topic: *ALERT* Debian warns its users to remove the Debian Multimedia repository  (Read 267 times)
40hz
Supporting Member
**
Posts: 8,510


/away

plarker much see users location on a map View Profile Give some DonationCredits to this forum member
« on: June 14, 2013, 07:36:53 AM »



This may end up being a tempest in a teacup. But for now, Debian is very concerned about one of its unnofficial software repositories and is now warning Debian users of a potential security problem should they install software from it.

Heise Online website posted this:

Quote
Users warned to remove Debian Multimedia repository

The Debian project is warning users that the unofficial Debian Multimedia repository now has to be considered unsafe. According to the Debian maintainers, the debian-multimedia.org domain is not being used by the maintainers of the unofficial repository any more and is now registered to a party unknown to the Debian project. This means that the repository is no longer safe to use and users should remove it from their sources.list file as soon as possible.

In its announcement, the Debian project is recommending that users check their systems by running

grep debian-multimedia.org /etc/apt/sources.list /etc/apt/sources.list.d/*

which will show debian-multimedia.org in its output if the user has the untrustworthy repository enabled. Meanwhile, Debian developer Steve Kemp has asked the community to create a tool for the distribution to easily manipulate entries in the sources.list file as Debian currently does not ship such a tool. At the moment, users have to edit their repository sources with a text editor.

Using unofficial repositories always represents a security risk and this example clearly shows one of the reasons, as the project usually does not have any control over such repositories. Since the new owners of the debian-multimedia.org domain are unlikely to have access to the signing keys for the expired repository, the security risk is somewhat mitigated as long as users do not install unsigned packages. In any case, removing the repository from one's sources file as Debian recommends is the best procedure to follow.

The official Debian announcement can be read here.
 ohmy
« Last Edit: June 14, 2013, 07:44:28 AM by 40hz » Logged
TaoPhoenix
Supporting Member
**
Posts: 2,297



Making a Post, Editing it twice to make it nice.

see users location on a map View Profile Give some DonationCredits to this forum member
« Reply #1 on: June 14, 2013, 07:51:18 AM »


Slashdot's copy of this story adds a "Debian is not so innocent" wrinkle though:

"If you're wondering where it went, it moved to deb-multimedia.org, after the DPL (at the time) asked the maintainer to stop using the Debian name."

http://lists.alioth.debia...ners/2012-May/026678.html

So ... if you tell a maintainer to stop using the Debian name ... they just might!?

Logged
40hz
Supporting Member
**
Posts: 8,510


/away

plarker much see users location on a map View Profile Give some DonationCredits to this forum member
« Reply #2 on: June 14, 2013, 09:06:13 AM »

The issue Debian has here isn't with the deb-multimedia.org repository per se. The problem is that whoever is currently the owner of debian-multimedia.org is not anyone who is known to Debian.

From Debian's announcement:

Quote
The unofficial third party repository Debian Multimedia stopped using the domain debian-multimedia.org some months ago. The domain expired and it is now registered again by someone unknown to Debian. (If we're wrong on this point, please sent us an email so we can take over the domain! Wink )

debian-multiedia.org may still be found in many user's software source lists. So Debian is concerned since it's no longer the location of what may now be found at deb-multimedia.org.

debian-multimedia.org is now owned by somebody called Mikhail Dashkel over in Russia. Apparently they have attempted to contact him and haven't received any response. So I think it's understandable that the powers at Debian are more than a little concerned about it right now. Especially considering the questionable legality of registering a domain with Debian's name in it.

I also don't really see where Debian is much at fault. They attempted to work out the maintenance and duplication problems cropping up between the d-m-o repository and Debian's official ones.

Debian said:



And they got back this very terse reply from the people responsible for d-m-o:


So from my perspective, the d-m-o folks have decided to go on their merry way rather than work things out on the duplication issue. After that, the discussion starts going downhill rapidly - as discussions are wont to do in the FOSS world whenever someone thinks somebody else just flipped them off. (You can find the whole discussion thread herein case anybody's interested.)
 smiley
Logged


[ may-june 2013 ad experiment; click here to learn more about donationcoder.com ]

Tuxman
Supporting Member
**
Posts: 1,279


OMG not him again!

View Profile WWW Give some DonationCredits to this forum member
« Reply #3 on: June 14, 2013, 09:37:00 AM »

People still use Linux?
Logged

I bet when Cheetahs race and one of them cheats, the other one goes "Man, you're such a Cheetah!" and they laugh & eat a zebra or whatever.
- @VeryGrumpyCat
TaoPhoenix
Supporting Member
**
Posts: 2,297



Making a Post, Editing it twice to make it nice.

see users location on a map View Profile Give some DonationCredits to this forum member
« Reply #4 on: June 14, 2013, 10:28:58 AM »


Sure, on target again 40hz.

I absolutely get that a former "trusted source" flips hands and then you have no idea where it goes - that's a classic precursor to malware vs less than aware users.

Logged
ewemoa
Honorary Member
**
Posts: 1,962



View Profile Give some DonationCredits to this forum member
« Reply #5 on: June 14, 2013, 09:11:14 PM »

Thanks for the headsup, 40hz.
Logged
40hz
Supporting Member
**
Posts: 8,510


/away

plarker much see users location on a map View Profile Give some DonationCredits to this forum member
« Reply #6 on: June 14, 2013, 09:27:53 PM »

Thanks for the headsup, 40hz.

You're welcome. But thanks is really due Heise Online's The H-Open site. Kiss  A daily must visit if you're at all into FOSS.
 Thmbsup
Logged
ewemoa
Honorary Member
**
Posts: 1,962



View Profile Give some DonationCredits to this forum member
« Reply #7 on: June 15, 2013, 04:35:35 AM »

Thanks for the headsup, 40hz.

But thanks is really due Heise Online's The H-Open site. Kiss

As they seem to have feeds I'll give one a try for a while.  Thanks for the tip smiley
Logged
Pages: [1]   Go Up
  Reply  |  New Topic  |  Print  



[ may-june 2013 ad experiment; click here to learn more about donationcoder.com ]


 
Jump to:  
   Forum Home   Thread Marks Chat! Downloads Search Login Register  

DonationCoder.com | About Us
DonationCoder.com Forum | Powered by SMF
[ Page time: 0.055s | Server load: 0.35 ]