5 ms·
If it's cryptographically signed and you found the public key from a more reputable place, you are ok. This is how apt repositories work - they use HTTP, but si
by 0942v8653 10y ago
If it's cryptographically signed and you found the public key from a more reputable place, you are ok. This is how apt repositories work - they use HTTP, but since everything is signed, mitm attacks can't do much other than see which packages you install.
- Sephr 10y agoAlmost nobody is going to search for external sources to verify the content on keepass.info > mitm attacks can't do much other than see which packages you install On the contrary, if you MitM the entire downloads page you can simply offer up a hacked/backdoored version of the software. There is no signature check if you remove the signature check in the version that you distribute.
- mseebach 10y agoThat's the fundamental trust-bootstrapping problem. You need an independent way to establish trust in the first interaction. In SSL, it's the (very flawed) CA model (never mind that nothing about SSL protects you if the website content is compromised). In this case, you can verify the download file signatures on keybase.io which is probably significantly safer than the CA model is. Sure, in this day and age, it's slightly disconcerting to see a security-related website that isn't SSL, but on the other hand, the tendency to blindly trust the green padlock is probably even more dangerous. http://keepass.info/integrity_sig.html http://keepass.info/integrity_sig.html https://keybase.io/reichl https://keybase.io/reichl
- tekklloneer 10y agoI don't really see how this is relevant. It may be flawed, but clowning the CA model is beyond the abilities of the vast majority of attackers.
- mseebach 10y agoSetting up a MITM attack is not exactly trivial, either.
- ygjb-dupe 10y agoUh, sure. But TBH, if I am going to go through the trouble of MITM'ing the site, then I am going to rewrite the site to: * include my awesome fingerprint * link to my awesome key * link to my l33t entry on keybase Side note - the CA model has issues, but in what world is pointing users to a VC funded startup that has only been around for two years "safer" than the flawed, but well understood security model of the CA system? I don't mean to impugn Keybase, from watching them I like what they are doing, but bootstrapping trust based on content they control is hardly ideal, and I would be shocked to hear someone say that Keybase is more reliable or more trustworthy than the CA/Browser Forum (10 years old) and the browser vendors (>20 years old depending on vendor/code base).