3 ms·
It's definitely an issue that the sha256 checksum check was broken. But, can someone explain why a person who is MITM'ing ipk downloads would change the packag
by pkgsupplysec 7y ago
It's definitely an issue that the sha256 checksum check was broken.
But, can someone explain why a person who is MITM'ing ipk downloads would change the package and not the checksum?
Are there GPG signatures of the package checksums signed with a key that ships with the release?
Are package repos downloaded over HTTPS? Is there a CA bundle in the release with which repo x.509 certs are validated?
- slrz 7y agoThe SHA-2 checksums to verify packages against are delivered as part of the (signed) package index (as the article alludes to).
- pkgsupplysec 7y agoAnd those package repo sha256 checksums are signed and verified with ed25519 by usign and ucert (with a key built into the firmware) usign: https://git.openwrt.org/project/usign.git https://git.openwrt.org/project/usign.git ucert: https://git.openwrt.org/project/ucert.git https://git.openwrt.org/project/ucert.git Firmware releases are also signed with GPG: https://openwrt.org/docs/guide-user/security/release_signatures https://openwrt.org/docs/guide-user/security/release_signatu... openwrt/openwrt: https://github.com/openwrt/openwrt https://github.com/openwrt/openwrt openwrt/packages: https://github.com/openwrt/packages https://github.com/openwrt/packages openwrt/openwrt/search?q="usign" https://github.com/openwrt/openwrt/search?q=usign https://github.com/openwrt/openwrt/search?q=usign
- procombo 7y agoI installed newest version OpenWRT on a popular brand, recently manufactured wireless router last week. The OpenWRT firmware couldn't access https sites without installing multiple packages first. Then they had me install all the root certs over an unencrypted connection. The opkg repos and install files are all downloaded over http. With full seriousness, I really hope nobody expects operational security using these routers.
- bloopernova 7y agoOof. Well I hope that this episode has a positive outcome in that OpenWRT improve their install and packaging security.
- KCUOJJQJ 7y ago>The opkg repos and install files are all downloaded over http. This was a problem because of the bug. But now it isn't one anymore. 'opkg update' updates the package lists. The lists contain information about the packages: name, file size, architecture, description etc., and also the SHA256sum. When you install a package opkg will compare the SHA256sums.