[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#499897: preventing replay attacks against the security archive



Quoting Eugene V. Lyubimkin (jackyf.devel@gmail.com):

> doesn't allow seeing previous Release files while deciding accept or decline just
> downloaded one -> apt ABI bump may be needed. And this is also another pain for Christian,
> we just done last (we hope) translation changes for apt.


Well, between a potential security issue and pain for APT localizers,
I think the choice is clear.

In short, don't count APT localization as a blockr for this issue if
it is wished for lenny. I will of course appreciate to have the
opportunity to give translators a translation update window.

I propose that what we currently have in the debian-sid bzr branch is
uploaded for lenny, then, *if the "prevent replay attacks" patch is
chosen for lenny* to immediately apply it in that debian-sid bzr
branch and I launch a short translation update round for the 10 days
needed for the former version to reach testing.

(keeping the original CC list, which is probably overflated, sorry)

Attachment: signature.asc
Description: Digital signature


Reply to: