Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Online intruders hit Red Hat, Fedora Project
Robert Lemos, SecurityFocus 2008-08-22

Unknown intruders breached the security of several computers used by Linux firm Red Hat and the Fedora Project, forcing administrators to take the systems offline for over a week, Fedora and Red Hat announced on Friday.

Comments Mode:
key 2008-08-25
Anonymous (1 replies)
"the Fedora Project claimed that the intruders did not get the package signing key"

[...]

"we have high confidence that the intruder was not able to capture the passphrase used to secure the Fedora package signing key,"

so there is probably some misunderstanding here, they probably don't have the password, but may have the key (i wonder how long a bruteforce attack will take :)

btw, why were the keys on an online system? (not an isolated system, no airgap etc). amateur cryptography...

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11532/35235#35235
Re: key 2008-09-02
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus