1 |
On 170225-21:34-0600, R0b0t1 wrote: |
2 |
> On Saturday, February 25, 2017, Miroslav Rovis <miro.rovis@××××××××××××××.hr> |
3 |
> wrote: |
4 |
> > |
5 |
> https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html |
6 |
... |
7 |
> |
8 |
> Very interesting. The first useful SHA-1 collision was, if I remember, done |
9 |
> in 2015, and subverted an HTTPS certificate (though not one which had been |
10 |
> issued). This was some guys with a couple of servers lined with graphics |
11 |
> cards. |
12 |
> |
13 |
> Seeing someone manage to do it in a garage a number of years before it was |
14 |
> cosidered feasible should, hopefully, make you have more conservative |
15 |
> estimates of the strength of modern cryptography. |
16 |
> |
17 |
> Aside: |
18 |
> http://ecrypt-eu.blogspot.com/2015/11/break-dozen-secret-keys-get-million.html |
19 |
|
20 |
Too technical for me. Too little learning gain for too much mumbo-jumbo noise, at this |
21 |
stage of my understanding of crypto, for me. |
22 |
|
23 |
> R0b0t1. |
24 |
|
25 |
But, when we talk crypto being broken, I can help thinking of other |
26 |
threats to Gentoo and other FOSS GNU Linux that I fear are perfectly |
27 |
feasible (for the resourceful subjects) |
28 |
|
29 |
Gentoo distro is increasingly served the insecure way, IMO, that is: via |
30 |
git, without the repositories being, for end users, PGP-verifiable. |
31 |
|
32 |
And via a new private big business, the Github. Giving over all users to |
33 |
big Github brother. |
34 |
|
35 |
And, in the trasition all the history got lost. Git started remembering |
36 |
only from 2015. |
37 |
|
38 |
I have asked a question about getting git-served repository verifiable |
39 |
for end users, but I didn't get any replies: |
40 |
|
41 |
Date: Tue, 20 Dec 2016 00:47:56 +0100 |
42 |
|
43 |
Message-ID: <20161219234756.GA4008@×××.xdwgrp> |
44 |
|
45 |
Subject: Is it safe to switch from webrsync to the git repo now? |
46 |
|
47 |
if you are subscribed and have three month worth of gentoo-user mail in |
48 |
your inbox |
49 |
|
50 |
or: |
51 |
|
52 |
(same subject as above of course) |
53 |
https://lists.gt.net/gentoo/dev/320922 |
54 |
|
55 |
Long term, this is an issue that will not go away unless it is fixed, |
56 |
i.e. git-served portage packages start being PGP-verifiable for end |
57 |
users. |
58 |
|
59 |
And when we talk security for privacy, and with... pretty much (at least |
60 |
from my perspective) privacy experts of today, how about this: |
61 |
|
62 |
[Secure Desktops] dbus, gnunet (was: unstable dnssec-root) |
63 |
https://secure-os.org/pipermail/desktops/2017-February/000180.html |
64 |
|
65 |
( |
66 |
where note the dbus creating encrypted session, and the link thereto: |
67 |
How to avoid stealth installation of systemd? |
68 |
http://forums.debian.net/viewtopic.php?f=20&t=116770&start=45#p552566 |
69 |
|
70 |
) |
71 |
|
72 |
Regards! |
73 |
- |
74 |
Miroslav Rovis |
75 |
Zagreb, Croatia |
76 |
https://www.CroatiaFidelis.hr |