[Nix-dev] NIX_OTHER_STORES and security?

Marc Weber marco-oweber at gmx.de
Tue Nov 25 17:41:21 CET 2008


Arie Middelkoop is right.

What happens if a user subscribes to a channel which contains malicious
packages? I mean if the user installs a malicious package this way and
the sysadmin does so as well but maybe two days later. Then the sysadmin
won't install anything but reuse the existing (manipulated) store path..

Am I missing a point here?

Sincerly
Marc Weber



More information about the nix-dev mailing list