4 ms·
They are still using MD5 checksums?
by knweiss 16y ago
They are still using MD5 checksums?
- dublinclontarf 16y agoWhat should they be doing?
- deleted 16y ago[deleted]
- marcus 16y agoConsidering the fact that gmane.com isn't secured, both are useless from a security viewpoint. It would be easier to intercept the request http://permalink.gmane.org/gmane.emacs.announce/17 http://permalink.gmane.org/gmane.emacs.announce/17 and change the checksum that appears in the HTML, than to generate a new .tar.gz with the original checksum. If you can't trust that no one tampered with the checksum what good is it???
- DrSprout 16y agoQuickly checking that you have the latest release in the absence of a good network connection. Also, you can use mirrors without worrying about the mirrors being tampered with. Obviously if someone does a MITM on you against gmane you're in trouble.
- cstuder 16y agoAll hashes suffer from collisions (Otherwise they would be great compression tools). But a collision to an arbitrary MD5 hash cannot yet be easily calculated. And producing a working (malware) binary with the same hash would be quite a challenge. So no, for these purposes, MD5 doesn't post a problem.
- doty 16y agoThat doesn't appear to be true. From http://www.mscs.dal.ca/~selinger/md5collision/ http://www.mscs.dal.ca/~selinger/md5collision/: It is now well-known that the crytographic hash function MD5 has been broken. [...] The following is an improvement of Diaz's example, which does not need a special extractor. Here are two pairs of executable programs (one pair runs on Windows, one pair on Linux) [...] Here, you can download the software that I used to create MD5-colliding executable files.
- tumult 16y agoThe person doing the spoofing has to create both of the files. You can't take an existing file created by a third party, and then generate a collision against it (yet).
- jozwiakjohn 16y agoSure you can, if you have arbitrarily long but still finite time. (Think recursive versus recursively enumerable sets.)
- lambda 16y agoWhen he says "can't", he doesn't mean it's impossible, he means it's infeasible. There are no techniques for doing it fast enough that anyone has to worry about it being done.
- ahn 16y agoThey are using digital signatures(Chong Yidong's). The following files are both available from the same places as the tarballs: emacs-23.2.tar.gz.sig emacs-23.2.tar.bz2.sig