Security concern regarding prebuilt images #11
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Following up on our conversation here and because you answered this:
I'm now really concerned about my security and would like to know the origin of these images. I have a lot of private and NDA documents on my drives.
Should I worry?
Thank you in advance!
Fair question. The image isn't a binary from an unknown source. It's built with build-rootfs.sh (right here in this repo), which runs Debian's debootstrap and uses the official mirrors (deb.debian.org). Every package in it is a signed, official Debian package. The script just assembles them into a tarball so the install is fast and works offline. No 3rd party packages.
If you'd rather not trust a prebuilt tarball at all, you have two options:
FYI, any OS installer (including official Debian ISOs) runs with full disk access, so verify what you install and keep backups. But butterknife is not that special
@drew Awesome. Thank you very much. Closing then. Cheers!