3 ms·
> There is no way to securely deploy a package directly from the internet. Fetching a file from the internet and verifying it against a hash or signature is th
by Perseids 10y ago
> There is no way to securely deploy a package directly from the internet.
Fetching a file from the internet and verifying it against a hash or signature is the only way to securely deploy a package from the internet. This is exactly one of the use cases theses cryptographic primitives are built for. Don't blame the users when they utilize the tools the way they are supposed to be, blame the tools when they fail when doing so.
And by the way, if you ever need to run `apt-get upgrade` or `apt-get install` on your production server from a public mirror, then you are guilty of "deploying a package directly from the internet", too. (My apologies and congratulations if don't.)
- raverbashing 10y agoapt-get can (and do) check signatures of repos But yeah, you could put an unverified repos to be used
- lmm 10y agoGit has tag signing, surely there's a way to clone a specific tag and check the signature against a specific GPG key fingerprint?
- heartsucker 10y agogit checkout 0.1.0 git tag -v 0.1.0
- nhaehnle 10y agoTag signatures only cover the mapping from tag name to commit hash. In other words, specifying a manually-verified commit hash is actually more secure. Tag signatures are mostly worthless now from a crypto point of view -- with the caveat that you can still get some value from them if you still trust sha1 to be secure against second-preimage attacks.
- Perseids 10y agoFor the argument at hand (Can you deploy anything on a production server from a third party that is only verified cryptographically?) signatures and hashes fulfill the same function (and btw I also wrote "verifying it against a hash or signature" above). More to the point, under the hood GPG signatures only sign a hash of the file in question anyway. Verifying a file via a GPG signature is strictly less secure than verifying it by its hash (assuming you use the same hash function as the signature).