-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Marc Ballarin wrote:
> Of course. It is just in *no* way specific to Gentoo. rsync mirrors can be
> compromised, but so does kernel.org, microsoft.com or any other server.
> Digital signatures aren't used very often, because they are rather
> difficult to handle, and can only solve the problem at one level.
Actually, kernel.org *does* sign their downloads; their public key is
available on any of the major TTP PGP servers (from which you download
using SSL signed by a trusted CA who's cert you already have installed
from when you got your computer or whatever). Microsoft at the very
least uses SSL of the same nature, but I suspect they also use digital
signatures on each package to provide the same security; I'm sure the
public key was pre-distributed with your computer.
RedHat provides the same faculty, based on GPG, with up2date. Many other
distros (Debian, for instance), do not, as far as I know, address this
problem in any way.
So it's not like we're really far behind the 8 ball here, but this *is*
a possible problem, the fix is well understood and implementable, and
some people do already fix it (and, in my opinion, it would be negligent
not to).
You *are* correct in highlighting the conditions that make this
exploitable, but they are not all that difficult to achieve (man in the
middle being pretty simple, if someone has access; compromised rsync
mirrors having happenned before).
I'm not tearing out my hair over this, and I'm still using Gentoo. But
it's worth noting that this is a risk that should be addressed.
- --
Dan "KrispyKringle" Margolis
Security Coordinator/Audit Project, Gentoo Linux
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)
iQEVAwUBQY5WZ7DO2aFJ9pv2AQKw2wgAnRt2Nr9835/eJmYVunFobnTzkOH8lYC1
F73s+i5iILZZd9Ljx0eo2B5+blATmcAcNQLkGmEfbjBK513OgZr0B+3bB2BvLVrN
m5S1h5VmHqST4n/IY0O1R4Kh8GZ8QHXyr91SEcsVtFLD+4Jiauqi9hamm8rI+P4M
Q72Ie1Kl6WIfDiqHAdfzYFenkFwNah/F3fkvWiosR2AHJbVSCXwcWiSAkZHXUaeu
XP05W7NEko/JjXmSeBdEEIaA2b3hjBC2PmVdTs8NmMDUgtbj2aQjE/FQfpIDotW7
puNPVlWVX5Oci6b21eiC65rmyiTdzI8BfoWot5tqSLsoUUHg8TbRBQ==
=xXwC
-----END PGP SIGNATURE-----
--
gentoo-security@g.o mailing list
|