Gentoo Archives: gentoo-security

From: Gregory Symons <gsymons@××××××××××××.biz>
To: gentoo-security@l.g.o
Subject: [gentoo-security] Re: Weird Network and Portage Digest Issues
Date: Thu, 26 Aug 2004 01:51:20
Message-Id: cgjecm$8ff$1@sea.gmane.org
In Reply to: Re: [gentoo-security] Weird Network and Portage Digest Issues by Chris Wensink
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 Chris Wensink wrote:
5
6 | Does anyone know of some sort of md5 checksum package / procedure to
7 | verify the integrity of a package download and test it, before
8 | configuring, compiling and installing it? Maybe this is the next
9 | thing a talented programmer needs to build to prevent problems like
10 | this in the future.
11
12 That's what portage is doing when it checks the md5 checksum. It
13 compares the md5 of the source package you download with the one that's
14 stored in portage. Granted, it's still vulnerable--someone could
15 compromise portage itself and change the checksums--but it's better than
16 nothing. It's also fairly difficult to compromise portage, at least for
17 a long enough period of time to get a decent penetration of a trojaned
18 package, and time to exploit the trojan. Not impossible, but difficult
19 enough that I'm satisfied with the existing security, at least until
20 someone writes something better. It's not something I lose sleep over.
21
22 Greg
23 -----BEGIN PGP SIGNATURE-----
24 Version: GnuPG v1.2.4 (GNU/Linux)
25 Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
26
27 iD8DBQFBLT0x0LRNiXV/8IARAjUwAJ9M8GvWB+c1NJqyuaCl2WT5LcSO3ACcDQwy
28 0CFob7ATmFMmBsoSBdCh0Jc=
29 =gwP8
30 -----END PGP SIGNATURE-----
31
32
33 --
34 gentoo-security@g.o mailing list