1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Marc Ballarin wrote: |
5 |
> Of course. It is just in *no* way specific to Gentoo. rsync mirrors can be |
6 |
> compromised, but so does kernel.org, microsoft.com or any other server. |
7 |
> Digital signatures aren't used very often, because they are rather |
8 |
> difficult to handle, and can only solve the problem at one level. |
9 |
|
10 |
Actually, kernel.org *does* sign their downloads; their public key is |
11 |
available on any of the major TTP PGP servers (from which you download |
12 |
using SSL signed by a trusted CA who's cert you already have installed |
13 |
from when you got your computer or whatever). Microsoft at the very |
14 |
least uses SSL of the same nature, but I suspect they also use digital |
15 |
signatures on each package to provide the same security; I'm sure the |
16 |
public key was pre-distributed with your computer. |
17 |
|
18 |
RedHat provides the same faculty, based on GPG, with up2date. Many other |
19 |
distros (Debian, for instance), do not, as far as I know, address this |
20 |
problem in any way. |
21 |
|
22 |
So it's not like we're really far behind the 8 ball here, but this *is* |
23 |
a possible problem, the fix is well understood and implementable, and |
24 |
some people do already fix it (and, in my opinion, it would be negligent |
25 |
not to). |
26 |
|
27 |
You *are* correct in highlighting the conditions that make this |
28 |
exploitable, but they are not all that difficult to achieve (man in the |
29 |
middle being pretty simple, if someone has access; compromised rsync |
30 |
mirrors having happenned before). |
31 |
|
32 |
I'm not tearing out my hair over this, and I'm still using Gentoo. But |
33 |
it's worth noting that this is a risk that should be addressed. |
34 |
- -- |
35 |
Dan "KrispyKringle" Margolis |
36 |
Security Coordinator/Audit Project, Gentoo Linux |
37 |
-----BEGIN PGP SIGNATURE----- |
38 |
Version: GnuPG v1.2.4 (Darwin) |
39 |
|
40 |
iQEVAwUBQY5WZ7DO2aFJ9pv2AQKw2wgAnRt2Nr9835/eJmYVunFobnTzkOH8lYC1 |
41 |
F73s+i5iILZZd9Ljx0eo2B5+blATmcAcNQLkGmEfbjBK513OgZr0B+3bB2BvLVrN |
42 |
m5S1h5VmHqST4n/IY0O1R4Kh8GZ8QHXyr91SEcsVtFLD+4Jiauqi9hamm8rI+P4M |
43 |
Q72Ie1Kl6WIfDiqHAdfzYFenkFwNah/F3fkvWiosR2AHJbVSCXwcWiSAkZHXUaeu |
44 |
XP05W7NEko/JjXmSeBdEEIaA2b3hjBC2PmVdTs8NmMDUgtbj2aQjE/FQfpIDotW7 |
45 |
puNPVlWVX5Oci6b21eiC65rmyiTdzI8BfoWot5tqSLsoUUHg8TbRBQ== |
46 |
=xXwC |
47 |
-----END PGP SIGNATURE----- |
48 |
|
49 |
-- |
50 |
gentoo-security@g.o mailing list |