Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [News item review] Portage rsync tree verification (v2)
Date: Thu, 25 Jan 2018 22:21:13
Message-Id: robbat2-20180125T221502-520102938Z@orbis-terrarum.net
In Reply to: Re: [gentoo-dev] [News item review] Portage rsync tree verification (v2) by Alon Bar-Lev
1 On Thu, Jan 25, 2018 at 11:55:58PM +0200, Alon Bar-Lev wrote:
2 > I did not looked into the detailed implementation, however, please
3 > make sure integrity check handles the same cases we have applied to
4 > emerge-webrsync in the past, including:
5 Gemato is the implementation of GLEP74/MetaManifest, which DOES
6 explicitly address both of these concerns.
7
8 > 1. Fast forward only in time, this is required to avoid hacker to
9 > redirect into older portage to install vulnerabilities that were
10 > approved at that time.
11 Replay attacks per #1 are addressed via TIMESTAMP field in MetaManifest.
12
13 > 2. Content integrity, especially removal, as far as I understand, the
14 > mechanism will not enable to detect authorized removal of content.
15 I think you meant 'unauthorized' rather than 'authorized' here.
16 It will detect files that are expected to exist but are missing.
17
18 --
19 Robin Hugh Johnson
20 Gentoo Linux: Dev, Infra Lead, Foundation Treasurer
21 E-Mail : robbat2@g.o
22 GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85
23 GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies