3 ms·
Arbitrary package attack - fixed >4 years ago, requires explicit config to enable downgrade, but some distros screw that up Replay and Freeze attacks -- Ouch!
by _wmd 8y ago
Arbitrary package attack - fixed >4 years ago, requires explicit config to enable downgrade, but some distros screw that up
Replay and Freeze attacks -- Ouch! sounds like every repo should set an aggressive Valid-Until (24 hours?). This attack still works with a compromised SSL mirror, and seems (according to the link below) to already be addressed as of at least 5 months ago
Extraneous Dependencies -- sounds like a bug in apt, also manifests for a compromised TLS mirror.
Endless Data -- nothing to do with GPG or TLS
Improper error handling in APT -- 18 month old bug
apt-key silently fails to remove GPG keys -- unfortunate and doubtlessly due to gnupg's lack of a real API
Conclusion -- at least 3 of the listed bugs manifest identically with SSL, another 2 are fixable implementation bugs. None are issues endemic to using GPG in preference to SSL, and none exclusively support the article's conclusion to always use SSL. Post fails to contrast the GPG bugs situation with the fact that e.g. Heartbleed occurred during the same timeframe as the bugs that were mentioned, one of many crucial factors in deciding the relative security of either solution, post additionally fails to mention with GPG the root of trust is the repository signer, which is still required with SSL, SSL only protects 'last mile' and specifically does not protect against a compromised mirror
I must admit though, the replay attack is scary and a very nice find.
Be sure to also read https://whydoesaptnotusehttps.com/ https://whydoesaptnotusehttps.com/ to see the other side of the coin
Finally, consider perusing the list of OpenSSL CVEs since 2014: https://www.openssl.org/news/vulnerabilities.html https://www.openssl.org/news/vulnerabilities.html and the corresponding list for gnupg: https://nvd.nist.gov/vuln/search/results?form_type=Basic&results_type=overview&query=gnupg&search_type=all https://nvd.nist.gov/vuln/search/results?form_type=Basic&res... -- bearing in mind that when SSL is deployed the union of both lists applies, without SSL only the gnupg list applies
- lbeltrame 8y ago> unfortunate and doubtlessly due to gnupg's lack of a real API Doesn't GPGME (also developed by the GPG people) offer said API?
- jwilk 8y ago> Be sure to also read https://whydoesaptnotusehttps.com/ https://whydoesaptnotusehttps.com/ Comments on HN: https://news.ycombinator.com/item?id=16221563 https://news.ycombinator.com/item?id=16221563