On 05/17/2010 02:45 PM, Rahul Sundaram wrote:
On 05/17/2010 06:13 PM, Ralf Corsepius wrote:
> On 05/17/2010 02:39 PM, Rahul Sundaram wrote:
>
>> On 05/17/2010 06:03 PM, Ralf Corsepius wrote:
>>
>>
>>> Do I understand this correctly?
>>> * FESCO has a approved an installer which circumvents rpm?
>>>
>>> * This installer is installing to /usr/share?
>>>
>>>
>> That seems to be a misunderstanding. Autodownloader downloads data to
>> your home directory.
>>
> OK, it opens up the gates to worms and viruses.
>
Can you explain how? Autodownloader has a hash of the files that it
downloads and verifies them.
$HOME == automated arbitrary access to arbitrary user data == arbirary
option to install maliculous programs (viruses, spyware etc.).