Author: James Courtier-Dutton Date: To: lug, Hampshire LUG Discussion List Subject: Re: [Hampshire] Www.kernel.org down
On 10 September 2011 18:56, Vic <lug@???> wrote: >
>> But what does that say about the DR procedures?
>
> It says that they are not so arrogant as to presume that an unexpected
> intrusion can be put right just by restoring the service that has shown
> itself to be insecure...
>
>> Most DR would hope to get some sort of service back online within 48
>> hours.
>
> It would be a simple matter to get the same service back up within 48
> hours - and then someone will break in through exactly the same security
> hole.
>
> The kernel.org maintainers have got it right - understand the problem
> before pretending it has been fixed.
>
As far as I know, they don't in fact know how it was done.
That is the most worrying part.