From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756537Ab1JEVZb (ORCPT ); Wed, 5 Oct 2011 17:25:31 -0400 Received: from filtteri1.pp.htv.fi ([213.243.153.184]:49110 "EHLO filtteri1.pp.htv.fi" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753795Ab1JEVZa (ORCPT ); Wed, 5 Oct 2011 17:25:30 -0400 Date: Thu, 6 Oct 2011 00:25:26 +0300 From: Adrian Bunk To: Greg KH Cc: "Ted Ts'o" , "Frank Ch. Eigler" , Valdis.Kletnieks@vt.edu, "H. Peter Anvin" , "Rafael J. Wysocki" , Linux Kernel Mailing List Subject: Re: kernel.org status: establishing a PGP web of trust Message-ID: <20111005212526.GD14406@localhost.pp.htv.fi> References: <20111003180441.GD3072@localhost.pp.htv.fi> <34045.1317760188@turing-police.cc.vt.edu> <20111004223932.GA3460@localhost.pp.htv.fi> <20111004231730.GB17089@redhat.com> <20111005075438.GA29441@localhost.pp.htv.fi> <20111005170616.GD4297@thunk.org> <20111005192349.GA14406@localhost.pp.htv.fi> <20111005195024.GB14406@localhost.pp.htv.fi> <20111005200944.GB12876@suse.de> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20111005200944.GB12876@suse.de> User-Agent: Mutt/1.5.21 (2010-09-15) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Oct 05, 2011 at 01:09:44PM -0700, Greg KH wrote: > On Wed, Oct 05, 2011 at 10:50:24PM +0300, Adrian Bunk wrote: > > [1] I did check what Greg recommended in his email, but I'm not gonna > > wipe my complete installation (including wiping /home) unless > > someone can point at something indicating that there's a break-in > > at my machine. > > What would you consider "proof" of a break-in on your machine that would > cause you to be willing to reinstall it? There is no clear definition. Had debsums told me that /bin/bash was modified I would have been quite convinced. Externally observed suspicious behavior of my machine I could not explain. Or many other things - after all I am a person with some basic understanding of security and how computers work. When I am convinced there was a break-in on my machine, I also have to assume that all important and not so important accounts I have anywhere (from unbelievably many Bugzilla accounts to machines where I have root access) are also compromised, and have to act accordingly. It is possible to convince me that there was likely a break-in on my machine, but I am not assuming the worst case automatically, and for going through that horror of assuming it happened I need to see something clearly pointing at my machine. > greg k-h cu Adrian -- "Is there not promise of rain?" Ling Tan asked suddenly out of the darkness. There had been need of rain for many days. "Only a promise," Lao Er said. Pearl S. Buck - Dragon Seed