pacman hook security question #463
-
|
I'm fairly new to Arch and sbctl, and this is just a very remote possibility, but I was looking at the pacman hook and the source code, and I was wondering if it would be possible for an attacker to replace one of the files in the (necessarily-unencrypted) ESP with a malicious one of the same name that's already in the 'enrolled file database' of |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 1 reply
-
|
Maybe change to use NeedsTargets, and use |
Beta Was this translation helpful? Give feedback.
-
|
See the discussion here #228 |
Beta Was this translation helpful? Give feedback.
See the discussion here #228