4 ms·
A digital signature does not protect you against a malicious actor who starts distributing outdated, vulnerable versions to you.
by adobrawy 2y ago
A digital signature does not protect you against a malicious actor who starts distributing outdated, vulnerable versions to you.
- BSDobelix 2y agoHow do i know you don't know what your talking about?....a mystery ;)
- adobrawy 2y agoI mean replay attack and freeze attack as described in https://doi.org/10.1145/1455770.1455841 https://doi.org/10.1145/1455770.1455841 . It's very likely that I'm not up to date on mitigations in individual package managers.
- BSDobelix 2y ago>all of these package managers have vulnerabilities that can be exploited by a man-in-the-middle or a malicious mirror. Well, that's how software is, but that article is from 2008 and things have gotten a lot better in the meantime (I think archlinux wasn't even signing their packages back then). If the distribution's private keyring isn't compromised and you don't have third-party repos, your packages are as trustworthy as your distribution team (and upstream).