14 ms·
I'm confused about something. OpenBSD is supposedly one of the most secure OSs in existence. So how is it possible that I cannot find any digital signatures fo
by webber89 14y ago
I'm confused about something.
OpenBSD is supposedly one of the most secure OSs in existence. So how is it possible that I cannot find any digital signatures for the downloadable ISOs? I've been searching all over Google and the mirrors, but nothing has come up.
One person has suggested to just order a CD set from them, but I don't think that's a good solution. Having a secure verified copy of an OS should not require ordering a physical "gold master" set of discs to compare against.
I mean, we have all the necessary crypto, and anyone can use it. Generate a GPG/PGP signature of the install ISO and that's it, you're done. A lot of people do it - Debian, Ubuntu, CentOS, all the big names... I mean seriously, even Arch Linux people do it, and until recently they didn't have package signing (now they do).
I'm not complaining or criticising OpenBSD, I'm just wondering about their attitude to this aspect of security. I would be very happy if anyone could elaborate on the topic.
- papsosouid 14y ago>Generate a GPG/PGP signature of the install ISO and that's it, you're done. And you are getting that signature from the same place you are getting the binaries you are worried about being tampered with? They don't bother with security theatre because they aren't interested in being performing artists.
- tptacek 14y agoHuh? The signing key isn't kept online, unlike the binaries. You "remember" OpenBSD's key once, and can detect if someone tries to replace it with a different key. You thought you were being witty with this "performing artists" stuff, but really this is just florid ignorance.
- statictype 14y agoI think his point was that many people keep the signature in the same place as the actual binaries (most directories of builds of OSS I've seen have a tarball and a corresponding hash in the same listing). I'll admit I'm probably ignorant about this, but I don't see the point in that. If someone can compromise the binaries, they can also modify the signature files that are sitting in the exact same place.
- tptacek 14y agoIt's fine to keep the signature in the same place as the binary. Simply being able to modify files won't allow you to produce a valid signature under a PGP key kept offline.
- danieldk 14y agoA signature is not the same thing as a hash or checksum. You could modify an ISO and replace the signature, however that would be your signature. To create a signature as say, the OpenBSD project, you would need their private key, which is (hopefully) carefully hidden on some private machine. So, putting the signature in the same directory as ISOs is a perfectly safe practice (assuming that strong asymmetric cryptography is used, and the private key is kept private).
- papsosouid 14y ago>I think his point was that many people keep the signature in the same place as the actual binaries Basically, except I meant the key not the signature.
- tptacek 14y agoYou get the key once and its fingerprint is published repeatedly.
- papsosouid 14y agoAnd look at all the linux distros that do that. Oh right, they don't. They just go "here's our public key" and people download it over ftp from the exact spot they are getting the binaries, do nothing to verify it, and pretend that got them security. Hence, theatre. Anyone who would actually do it right already has the tools to do so, ssh public keys work just like pgp public keys.
- tptacek 14y agoYou have no idea what you're talking about. Go troll somewhere else.
- webber89 14y agoIf the binaries get tampered with on the server, then the file will fail the verification. If the signature gets tampered with on the server, the file will also fail the verification. I don't see how any tampering can cause problems, provided the OpenBSD project team publishes their public key widely [0]. [0] There is an attack where the adversary distributes malicious binaries signed with a key that appears to belong to the OpenBSD project, but which in reality would belong to the adversary. This could work if the adversary manages to mislead the user, but if the OpenBSD project team uploaded their public key all over the Internet (and preferably announce it on the mailing lists and home page), then this attack is ineffective. During signature verification, the key ID that created the signature is displayed and the user would know that something is wrong if the signature has not created by the usual OpenBSD signing key.
- papsosouid 14y ago>If the signature gets tampered with on the server Sorry, I meant the key. As all the linux distros using PGP signing demonstrate, people don't bother to verify the key, they just accept it blindly and assume everything is cool. Since only 1 out of a million people ask for this, and of those only 1 out of a million would actually go through the correct procedure rather than just grabbing the key from the same place they are grabbing the binaries and not verifying it in any way, it isn't worth the effort. The 0.001% of the 0.001% already have the tools available to verify, it is just a bit of a pain to do. It isn't worth it for the openbsd devs to waste time making it easier for those people who wouldn't verify the key anyways to feel secure when they would be exactly as secure as they are now. That's what I mean by security theatre.
- tptacek 14y agoWhat you mean by security theater is that because some users don't verify binaries, it doesn't matter if anyone is able to verify binaries. You're trolling. Please go away.
- papsosouid 14y agoPlease, keep spamming "ur a troll!!1" like a child, it is very productive and adds a great deal to the discussions at HN. As I said, the 0.001% of the 0.001% who actually want to verify can already do so. Several mirrors have widely known ssh pubkeys.
- deleted 14y ago[deleted]
- tobiasu 14y agoThe install sets themselves are checked by the installer, you could for example get bsd.rd from one mirror and the sets from somewhere else.
- webber89 14y agoI know you can do that, but that's not the best solution. A signature of the install set made with a key known to belong to the OpenBSD project is probably a much better assurance of integrity and authenticity of the files. Besides, how do you know the files and their hashes are not modified en route to you? One rogue node on the way to you (think AT&T Room 641A, but with data modification abilities) is all it takes, unless the transfer is SSL encrypted. And I don't mean just between you and the mirror, possibly also between the developers and the mirror (I bet some people would be very interested in backdooring one of the most secure systems on the planet by compromising their install images). Modification wouldn't matter as much with a signature-based system, since anyone doing the verification correctly would notice the signature verification failing or the signature coming from the wrong key (see my other comment for more information).
- tobiasu 14y agoNo doubt there are better solutions. But nobody has implemented one yet. Despite some users making up advanced theories for the lack of certain functionality, it usually only comes down to a simple lack of time and resources...
- ams6110 14y agoIf you use OpenBSD, you should order a CD set. It supports the project.
- jrockway 14y agoAnd, I got mine a week ago. So you get everything a little sooner than you would by downloading.
- ghshephard 14y agoThe secure way of acquiring the Software is via CD.
- tedunangst 14y agoDoing it right is a pain in the butt. FWIW, literally anyone can sign the OpenBSD releases and say "If your download matches this signature, it's the same as I downloaded from six different mirrors on three continents." Nobody does.
- jms703 14y agoJust because it's signed doesn't mean it is authentic. Do you trust the keys it would be signed with? On the other hand, OpenBSD makes the source available. If you want truly pristine and trusted binaries/ISOs, you should download the source yourself, create your own release (they have docs for this), and sign it yourself. That's the right way to accomplish what you're asking.