4 ms·
on the contrary, many open source projects sign and hash their packages, to anyone that verifies the signature and hash, the tampering will be immediately appar
by throwaway64 15y ago
on the contrary, many open source projects sign and hash their packages, to anyone that verifies the signature and hash, the tampering will be immediately apparent.
- DanBC 15y agoMD5 hashing is known weak, and must not be used for security. MD5 hashing is currently used to give quick and simple check on transmission download errors, rather than malicious attacks.
- exDM69 15y agoThat's why you should use SHA-hashes when you need cryptographic security.
- loeg 15y agoAnyone who can backdoor a release on their FTP server can easily upload a new CHECKSUM file. Many users probably do not bother to check the hash. Even if you use public key crypto to sign the hash, users probably don't know your public key in advance. An attacker can sign their malicious hash with any valid public key they like.
- throwaway64 15y agoyes, and its turtles all the way down, but its much harder to compromise (multiple) key servers than a simple download mirror. Its also trivial to setup some sort of totally unknown checking setup, that downloads the packages daily and checks if they are properly signed, and activates big red sirens if it is not.