Gentoo Archives: gentoo-user

From: Miroslav Rovis <miro.rovis@××××××××××××××.hr>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] SHA-1 has just been broken
Date: Sun, 26 Feb 2017 11:00:49
Message-Id: 20170226110050.GB15474@g0n.xdwgrp
In Reply to: Re: [gentoo-user] SHA-1 has just been broken by R0b0t1
1 On 170225-21:34-0600, R0b0t1 wrote:
2 > On Saturday, February 25, 2017, Miroslav Rovis <miro.rovis@××××××××××××××.hr>
3 > wrote:
4 > >
5 > https://security.googleblog.com/2017/02/announcing-first-sha1-collision.html
6 ...
7 >
8 > Very interesting. The first useful SHA-1 collision was, if I remember, done
9 > in 2015, and subverted an HTTPS certificate (though not one which had been
10 > issued). This was some guys with a couple of servers lined with graphics
11 > cards.
12 >
13 > Seeing someone manage to do it in a garage a number of years before it was
14 > cosidered feasible should, hopefully, make you have more conservative
15 > estimates of the strength of modern cryptography.
16 >
17 > Aside:
18 > http://ecrypt-eu.blogspot.com/2015/11/break-dozen-secret-keys-get-million.html
19
20 Too technical for me. Too little learning gain for too much mumbo-jumbo noise, at this
21 stage of my understanding of crypto, for me.
22
23 > R0b0t1.
24
25 But, when we talk crypto being broken, I can help thinking of other
26 threats to Gentoo and other FOSS GNU Linux that I fear are perfectly
27 feasible (for the resourceful subjects)
28
29 Gentoo distro is increasingly served the insecure way, IMO, that is: via
30 git, without the repositories being, for end users, PGP-verifiable.
31
32 And via a new private big business, the Github. Giving over all users to
33 big Github brother.
34
35 And, in the trasition all the history got lost. Git started remembering
36 only from 2015.
37
38 I have asked a question about getting git-served repository verifiable
39 for end users, but I didn't get any replies:
40
41 Date: Tue, 20 Dec 2016 00:47:56 +0100
42
43 Message-ID: <20161219234756.GA4008@×××.xdwgrp>
44
45 Subject: Is it safe to switch from webrsync to the git repo now?
46
47 if you are subscribed and have three month worth of gentoo-user mail in
48 your inbox
49
50 or:
51
52 (same subject as above of course)
53 https://lists.gt.net/gentoo/dev/320922
54
55 Long term, this is an issue that will not go away unless it is fixed,
56 i.e. git-served portage packages start being PGP-verifiable for end
57 users.
58
59 And when we talk security for privacy, and with... pretty much (at least
60 from my perspective) privacy experts of today, how about this:
61
62 [Secure Desktops] dbus, gnunet (was: unstable dnssec-root)
63 https://secure-os.org/pipermail/desktops/2017-February/000180.html
64
65 (
66 where note the dbus creating encrypted session, and the link thereto:
67 How to avoid stealth installation of systemd?
68 http://forums.debian.net/viewtopic.php?f=20&t=116770&start=45#p552566
69
70 )
71
72 Regards!
73 -
74 Miroslav Rovis
75 Zagreb, Croatia
76 https://www.CroatiaFidelis.hr

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] SHA-1 has just been broken R0b0t1 <r030t1@×××××.com>
Re: [gentoo-user] SHA-1 has just been broken Andrew Savchenko <bircoph@g.o>