Gentoo Archives: gentoo-security

From: Heikki Levanto <heikki@×××.dk>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Thoughts on Package Security
Date: Tue, 17 Feb 2004 08:01:19
Message-Id: 20040217080102.GB8309@lsd.dk
In Reply to: Re: [gentoo-security] Thoughts on Package Security by guerrilla_thought
1 On Mon, 2004-02-16 at 22:20, Brian Klauss wrote:
2 > Why not take package security one step deeper to ensure the validity
3 > of every ebuild and source-tree?
4 >
5 > Instead of relying upon a master hash of the compressed package,
6 > create a hash for each source file, documentation, makefile, etc.
7
8 Sorry, I don't see what that would give. If the md5 of the compressed
9 archive is fine, then we know already that it has not been tampered
10 with. Ergo, all contained files are fine.
11
12 (except for the theoretical possibility of md5-sum collision, which is
13 unlikely to an astronomical degree, and not worth worrying about in real
14 world)
15
16 Heikki
17
18 --
19 Heikki Levanto LSD - Levanto Software Development <heikki@×××.dk>
20
21
22 --
23 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Thoughts on Package Security Brian Klauss <brklauss@×××××××××.net>