Gentoo Archives: gentoo-security

From: Dan Margolis <krispykringle@g.o>
To: Marc Ballarin <Ballarin.Marc@×××.de>
Cc: Peter Simons <simons@××××.to>, gentoo-security@l.g.o
Subject: Re: [gentoo-security] Is anybody else worried about this?
Date: Sun, 07 Nov 2004 17:08:16
Message-Id: 418E5667.4000307@gentoo.org
In Reply to: Re: [gentoo-security] Is anybody else worried about this? by Marc Ballarin
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Marc Ballarin wrote:
5 > Of course. It is just in *no* way specific to Gentoo. rsync mirrors can be
6 > compromised, but so does kernel.org, microsoft.com or any other server.
7 > Digital signatures aren't used very often, because they are rather
8 > difficult to handle, and can only solve the problem at one level.
9
10 Actually, kernel.org *does* sign their downloads; their public key is
11 available on any of the major TTP PGP servers (from which you download
12 using SSL signed by a trusted CA who's cert you already have installed
13 from when you got your computer or whatever). Microsoft at the very
14 least uses SSL of the same nature, but I suspect they also use digital
15 signatures on each package to provide the same security; I'm sure the
16 public key was pre-distributed with your computer.
17
18 RedHat provides the same faculty, based on GPG, with up2date. Many other
19 distros (Debian, for instance), do not, as far as I know, address this
20 problem in any way.
21
22 So it's not like we're really far behind the 8 ball here, but this *is*
23 a possible problem, the fix is well understood and implementable, and
24 some people do already fix it (and, in my opinion, it would be negligent
25 not to).
26
27 You *are* correct in highlighting the conditions that make this
28 exploitable, but they are not all that difficult to achieve (man in the
29 middle being pretty simple, if someone has access; compromised rsync
30 mirrors having happenned before).
31
32 I'm not tearing out my hair over this, and I'm still using Gentoo. But
33 it's worth noting that this is a risk that should be addressed.
34 - --
35 Dan "KrispyKringle" Margolis
36 Security Coordinator/Audit Project, Gentoo Linux
37 -----BEGIN PGP SIGNATURE-----
38 Version: GnuPG v1.2.4 (Darwin)
39
40 iQEVAwUBQY5WZ7DO2aFJ9pv2AQKw2wgAnRt2Nr9835/eJmYVunFobnTzkOH8lYC1
41 F73s+i5iILZZd9Ljx0eo2B5+blATmcAcNQLkGmEfbjBK513OgZr0B+3bB2BvLVrN
42 m5S1h5VmHqST4n/IY0O1R4Kh8GZ8QHXyr91SEcsVtFLD+4Jiauqi9hamm8rI+P4M
43 Q72Ie1Kl6WIfDiqHAdfzYFenkFwNah/F3fkvWiosR2AHJbVSCXwcWiSAkZHXUaeu
44 XP05W7NEko/JjXmSeBdEEIaA2b3hjBC2PmVdTs8NmMDUgtbj2aQjE/FQfpIDotW7
45 puNPVlWVX5Oci6b21eiC65rmyiTdzI8BfoWot5tqSLsoUUHg8TbRBQ==
46 =xXwC
47 -----END PGP SIGNATURE-----
48
49 --
50 gentoo-security@g.o mailing list