4 ms·
>The AIDE package is critical for secure deployments since it helps administrators monitor for file integrity on a regular basis. However, Ubuntu ships with som
by ericcholis 10y ago
>The AIDE package is critical for secure deployments since it helps administrators monitor for file integrity on a regular basis. However, Ubuntu ships with some interesting configuration files and wrappers for AIDE.
Critical for secure deployments and hosted on sourceforge.....
- jessaustin 10y agoMost users will get it through a distro package manager.
- seanp2k2 10y agoPlease excuse my ignorance, but what are better options for code hosting and collaboration?
- gravypod 10y agoAnything that doesn't alter your binaries from time to time. I seem to remember that being a "Feature" of a desperate SourceForge not to long ago.
- lhecker 10y agotl;dr: Slashdot and SourceForge have a new owner which removed all this nonsense from those sites - including the adware. I believe the average HN reader - including you - should be interested in this then: https://www.reddit.com/r/sysadmin/comments/4n3e1s/the_state_of_sourceforge_since_its_acquisition_in/ https://www.reddit.com/r/sysadmin/comments/4n3e1s/the_state_...
- x1798DE 10y agoAllegedly the most recent owners have reversed the earlier policies and are trying to reclaim SourceForge's previous sterling reputation, FYI. Seems reasonably credible. That said, I'm one of those people who bothers to check the signatures on binaries before installing them, so as long as I trust the signature and dev, doesn't much matter to me if I downloaded it from xxx-malware-binaries.biz.ru.
- vacri 10y agoYou get that 'for free' with apt-based systems, as packages are GPG-signed by default, and will throw up an error if the signature is missing or is not in your trust store.
- sp332 10y agoThey've been bought by a different company since then, and they've cleaned it up. https://news.ycombinator.com/item?id=11860752 https://news.ycombinator.com/item?id=11860752
- gravypod 10y agoAny company that resorts to practices that low will never regain my trust. Even if they were bought out by RMS himself, I'd never host any of my projects there. It's just something I don't think I'll ever support after what happened; it's a matter of principle.
- derefr 10y agoWho exactly has lost your trust? A company is a group of people, but a brand is not. Companies can sell brands off to other companies. You can choose to trust—or not trust—a company, but if a brand moves from one company to another, the trust (or lack thereof) adhered to the brand because of the company shouldn't come along with it. For an example: IBM made a brand of laptop called ThinkPad. Now Lenovo makes a brand of laptop called ThinkPad. IBM's ThinkPads were excellent; Lenovo's ThinkPads are average. They're two different products, produced by two different companies, that happen to share a brand because one company sold that brand to the other. The brand conveys absolutely no information about whether you should trust the product. The company owning the brand conveys 100% of the information.
- chucksmash 10y agoTrying to say "this brand was bought by another entity so now all that negative brand equity and well-deserved consumer ire it had earned before is null and void" seems a bit like trying to have your cake and eat it too. No employees came along with the brand? None of the decisionmakers responsible for the previous SourceForge derp over the past couple of years? It's a clean slate - tabula rasa? That's fine, but it'll take time for people to warm up to that idea. That's what happens when you abuse trust.
- JdeBP 10y ago
- RubyPinch 10y agoThe acquiring company removed that feature the moment they acquired SF