5 ms·
That’s what digital signatures are for. So yes.
by classics2 7y ago
That’s what digital signatures are for. So yes.
- monoideism 7y agoFair enough, I gladly use apt for the same reason. But I mean download unsigned executables over an unencrypted connection, like this site is by default. You do it?
- someguydave 7y agoyes. it's amusing how many people confuse transport layer security with application layer security.
- monoideism 7y agoI've published signed debian packages to PPAs, so I'm well aware. My question was in relation to a unsigned executable on an unencrypted http site, as the OP site loads by default. Would you download and run one?
- exikyut 7y agoI'd wager that a large number of the system integrators, firmware engineers and random developers scattered throughout the production chains of most of the hardware and some of the software that you're currently using have run completely untested code in scenarios orders of magnitude more hair-raising than this. The same is probably equivalently applicable to the hardware that was used to compile the compiler that compiled the compiler that compiled the compiler that you're using.
- jakeogh 7y agoIt's a good point. I got: http://www.spectrum-soft.com/download/mc12cd.zip http://www.spectrum-soft.com/download/mc12cd.zip sha3-256: 1e9c7d1ec04019446fa448fec74af36f53eaf6508def75068eb32ae0d7f5109a
- deleted 7y ago[deleted]
- t0ddbonzalez 7y agoNot sure what the drama is about... The installer is clean. https://www.virustotal.com/gui/file/773a060c5c824f6c47352deafd23241c48570d002a12b76c6e2d8c663562600e/details https://www.virustotal.com/gui/file/773a060c5c824f6c47352dea...
- ncmncm 7y agoHaha, good one!
- someguydave 7y agoWhile it's theoretically possible that a hostile party could modify the package in-transit over HTTP/TCP, it seems far more likely that the hacked package would be placed on the "legit-looking" webserver (by hacking the webserver). In this case, looking to the SSL transport layer as any kind of credibility enhancement to the unsigned binary is worse than ignoring it. Therefore, an unsigned binary is an unsigned binary, no matter the transport mechanism. I agree that distributing unsigned binaries is poor security practice, but I also think that it is dangerous to think that the transport of an unsigned binary over an SSL connection gives it any credibility.
- labawi 7y agoSo.. you haven't heard of automated MITM executable-patching (infecting) solutions? I believe I read about them a couple of years ago. Once implemented, it's much easier than hacking servers and more convenient to do targeted, semi-targeted, local network/cafe script-kiddie attacks, without it being easily detected. Unfortunately for attackers, these days people don't download and run unverified executables as often, especially over http, so you may need lots of patience if you want do infect a specific person.
- someguydave 7y agoI covered that in the portion of the comment where I mentioned http/tcp
- labawi 7y agoI would really love some data (or good reasoning) on how server attacks are overwhelmingly more likely, so much so that the false security impression increases risk. MITM executable patching attacks are not theoretical. AFAIU, the first hit on "mitm executable infection" [1] and an interceptor (ARP/wifi/whatever) is all a script kiddie needs. [1] https://n0where.net/mitm-pe-file-infector-peinjector https://n0where.net/mitm-pe-file-infector-peinjector
- 7y ago
- lonelappde 7y agoHow do you obtain an trusted signature over http?