Kernel.org explained

kernel.org
Commercial:No
Type:Open source repository
Language:English
Ipv6:Yes
Current Status:Active

kernel.org is the main distribution point of source code for the Linux kernel, which is the base of the Linux operating system.

The website and related infrastructure, which is operated by the Linux Kernel Organization,[1] host the repositories that make all versions of the kernel's source code available to all users. The main purpose of kernel.org is to host repositories used by Linux kernel developers and maintainers of various Linux distributions. Additionally, it hosts various other projects or their mirrors, including the Linux Documentation Project (LDP) and CPAN.[2] [3]

Since August 2014, kernel.org provides additional security by mandating two-factor authentication for commits performed to hosted Git repositories that contain source code of the Linux kernel, with support for both soft tokens and hard tokens.[4]

2011 security breach

On 28 August 2011, developers at kernel.org realized that there had been a major security breach. Intruders had gained root access to the system and added a trojan to the startup scripts. Developers reinstalled all the servers and investigated the origin of the attack.[5] It is likely, although not confirmed, that the kernel.org intrusion is related to the intrusions of LinuxFoundation.org and Linux.com websites that were determined shortly afterwards.[6] [7]

Git, a distributed and open-source source management system designed by Linus Torvalds to guarantee the integrity of the source code, is used to keep track of changes in the Linux source code. This and the fact that the source code is available to anyone and widely known makes any attempt to tamper with the source code fairly easy to detect and revert if required.[8] All that makes kernel.org not the primary repository, but rather a distribution point of the kernel sources.

Kernel.org was back online by November 2011, with the exception of a few secondary services.[9] A 27 year old resident of Florida, US was arrested in 2016 for the attack.[10]

See also

Notes and References

  1. Web site: 2013-12-05 . The Linux Kernel Organization . 2015-01-15 . Kernel.org . Linux Kernel Organization.
  2. Web site: 2014-09-02 . The Linux Kernel Archives - FAQ . 2015-01-16 . Kernel.org . Linux Kernel Organization.
  3. Web site: 2014-12-13 . Mirrors.kernel.org, a service of the Linux Kernel Archives . 2015-01-16 . Kernel.org . Linux Kernel Organization.
  4. Web site: Konstantin Ryabitsev . 2014-08-18 . Linux Kernel Git Repositories Add 2-Factor Authentication . dead . https://web.archive.org/web/20180131082600/https://www.linuxfoundation.org/blog/linux-kernel-git-repositories-add-2-factor-authentication/ . 2018-01-31 . 2014-08-22 . Linux.com.
  5. Web site: The cracking of kernel.org . 2011-08-31 . The Linux Foundation . Jonathan Corbet . 2011-11-08 . dead . https://web.archive.org/web/20111029105944/http://www.linuxfoundation.org/news-media/blogs/browse/2011/08/cracking-kernelorg . 2011-10-29 .
  6. Web site: Blog Archive ยป kernel.org down for maintenance? . Heimic . 2011-09-13 . 2014-03-02 . https://web.archive.org/web/20110923203507/http://www.heimic.net/2011/09/13/kernel-org-down-for-maintenance/ . 2011-09-23 . dead .
  7. Web site: kernel.org is down!. 16 September 2011.
  8. News: Kernel.org hacked, but Linux kernel safe thanks to git . Fahmida Y. Rashid . linuxfordevices.com . 2011-09-01 . 2011-11-08 . https://archive.today/20130127213718/http://www.linuxfordevices.com/c/a/News/Kernelorg-hacked/ . 2013-01-27 . dead .
  9. Web site: Who rooted kernel.org servers two years ago, how did it happen, and why?. Dan Goodin. Ars Technica. 2013-09-24. 2018-01-30.
  10. Web site: Feds pin brazen kernel.org intrusion on 27-year-old programmer. Ars Technica.