1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Chris Wensink wrote: |
5 |
|
6 |
| Does anyone know of some sort of md5 checksum package / procedure to |
7 |
| verify the integrity of a package download and test it, before |
8 |
| configuring, compiling and installing it? Maybe this is the next |
9 |
| thing a talented programmer needs to build to prevent problems like |
10 |
| this in the future. |
11 |
|
12 |
That's what portage is doing when it checks the md5 checksum. It |
13 |
compares the md5 of the source package you download with the one that's |
14 |
stored in portage. Granted, it's still vulnerable--someone could |
15 |
compromise portage itself and change the checksums--but it's better than |
16 |
nothing. It's also fairly difficult to compromise portage, at least for |
17 |
a long enough period of time to get a decent penetration of a trojaned |
18 |
package, and time to exploit the trojan. Not impossible, but difficult |
19 |
enough that I'm satisfied with the existing security, at least until |
20 |
someone writes something better. It's not something I lose sleep over. |
21 |
|
22 |
Greg |
23 |
-----BEGIN PGP SIGNATURE----- |
24 |
Version: GnuPG v1.2.4 (GNU/Linux) |
25 |
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org |
26 |
|
27 |
iD8DBQFBLT0x0LRNiXV/8IARAjUwAJ9M8GvWB+c1NJqyuaCl2WT5LcSO3ACcDQwy |
28 |
0CFob7ATmFMmBsoSBdCh0Jc= |
29 |
=gwP8 |
30 |
-----END PGP SIGNATURE----- |
31 |
|
32 |
|
33 |
-- |
34 |
gentoo-security@g.o mailing list |