Full Disclosure mailing list archives

Re: Evilgrade 2.0 - the update explotation framework is back


From: Jhfjjf Hfdsjj <taser3000 () yahoo com>
Date: Mon, 1 Nov 2010 09:36:24 -0700 (PDT)



I do not believe anyone is 'ptoposing' anything. All he said was that package
signing should not be taken as a silver bullet, for experience has shown that
the key's themselves are capable of being compromised if a vendor is
successfully attacked.

Exactly what I would expect from *.edu

I read differently,

Then by all means, elaborate.



      

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: