Language Selection

English French German Italian Portuguese Spanish

Red Hat fesses up to Fedora FOSS security fiasco

Filed under
Linux
Security

A week or so ago, end users of the Linux-based Red Hat Fedora OS were warned to avoid downloading packages due to an "issue in the infrastructure systems" which waved big red flags suggesting a security breach to many industry observers. Now Fedora has admitted Red Hat OpenSSH packages were compromised by two separate server intrusions...

It all started with a highly cryptic Fedora-Announce mailing list posting which stated that "The Fedora Infrastructure team is currently investigating an issue in the infrastructure systems. That process may result in service outages, for which we apologize in advance."

Fair enough, that kind of thing happens, apology accepted. What was less acceptable was the bit which went on to say that "We’re still assessing the end-user impact of the situation, but as a precaution, we recommend you not download or update any additional packages on your Fedora systems."

Now, most sane-brained people would read that and think 'avoid downloading packages on Fedora systems' + 'issue in the infrastructure systems' = SECURITY BREACH!

Indeed, that is precisely what most sane-brained people, as well as many journalists, did think. The online news feeds were full of pet theories as to what had happened to cause the widespread Fedora service outages.

The blogosphere likewise. Everyone was hinting at a security breach. Everyone, that is, apart from Fedora.

More Here




More in Tux Machines

Huawei, Fuchsia and More

  • Huawei will no longer allow bootloader unlocking (Update: Explanation from Huawei)

    "In order to deliver the best user experience and prevent users from experiencing possible issues that could arise from ROM flashing, including system failure, stuttering, worsened battery performance, and risk of data being compromised, Huawei will cease providing bootloader unlock codes for devices launched after May 25, 2018. [...]"

  • Fuchsia Friday: How ad targeting might be a hidden cost of Fuchsia’s structure
     

    Fuchsia, by its nature, comes with the potential for a handful of new opportunities for ad targeting. Let’s peer into the dark side of Fuchsia’s innovative features.

  • iPhone Quarter, ZTE Troubles, Facebook Troubles, Nokia Come-back
     

    So the past month or two? The Quarterly results cycle came in. The item often of great interest is the Apple iPhone performance. 52.2 million iPhones shipped and that gives roughly a flat market share compared to the year before, so about 14%-15%. I'll come and do the full math later of the quarterly data. That race is no longer in any way interesting.

    But two Top 10 smartphone brands ARE in the news. One who is facing imminent death and the other who is making a miraculous return-from-dead. So imminent death and current Top 10 brand first. ZTE. The Trump administration has put a massive squeeze on ZTE and the company is in serious trouble of imminent collapse. Then bizarrely, Trump reversed course and felt he needed to protect CHINESE employment (???) and after yet another typical Trump-mess, we now are at a Never-Neverland where Trump's own party Republicans are revolting against their President and well, ZTE may end up a casualty of this mess. We'll keep an eye on it.

  •  

What is an Arduino Board

Gone are the days when prototyping your electronic gadget required you to fiddle with the breadboard. Dirty design, unsteady wire connections and having to do too much to get simple stuff working. Arduino has solved all of that today. Read
more

How Linux Can Make Your Life Easier

Linux is an Operating System (more specifically a kernel) that provides an interface between the computer hardware and the user. Like Microsoft Windows and OS X, Linux provides a platform to the users, enabling them to carry out their daily chores on their beloved computer. And in case you dual-booted or installed Linux on your computer or are just curious to know how Linux can make your life easier, then, you are at the right place. Read
more

Fedora and Red Hat News