4 ms·
At least the package is signed. Curl can against a url that got high jacked
by menzoic 1y ago
At least the package is signed. Curl can against a url that got high jacked
- SparkyMcUnicorn 1y agoPackages can get hijacked too.
- lionkor 1y agoWhat is the difference between a random website or domain, and the package manager of a major distribution, in terms of security? Is it equally likely they get hijacked?
- lucianbr 1y agoThe issue is not the package manager being hijacked but the package. And the package is often outside the "major distribution" repository. That's why you use curl | bash in the first place. Your question does not apply to the case discussed at all, and if we modify it to apply, the answer does not argue your point at all.
- serbuvlad 1y agoIt's singed by a key that's obtained from a URL owned by the same person. Sure, you can't attack devices already using the repo, but new installs are fair game. And are URLs (w/ DNSSEC and TLS) really that easy to hijack?
- tart-lemonade 1y ago> And are URLs (w/ DNSSEC and TLS) really that easy to hijack? During the Google Domains-Squarespace transition, there was a vulnerability that enabled relatively simple domain takeovers. And once you control the DNS records, it's trivial to get Let's Encrypt to issue you a cert and adjust the DNSSEC records to match. https://securityalliance.notion.site/A-Squarespace-Retrospective-or-How-to-Coordinate-an-Industry-Wide-Incident-Response-fead693b66c14543a48283d85aec19ad https://securityalliance.notion.site/A-Squarespace-Retrospec...