4 ms·
>If the signature gets tampered with on the server Sorry, I meant the key. As all the linux distros using PGP signing demonstrate, people don't bother to veri
by papsosouid 14y ago
>If the signature gets tampered with on the server
Sorry, I meant the key. As all the linux distros using PGP signing demonstrate, people don't bother to verify the key, they just accept it blindly and assume everything is cool. Since only 1 out of a million people ask for this, and of those only 1 out of a million would actually go through the correct procedure rather than just grabbing the key from the same place they are grabbing the binaries and not verifying it in any way, it isn't worth the effort. The 0.001% of the 0.001% already have the tools available to verify, it is just a bit of a pain to do. It isn't worth it for the openbsd devs to waste time making it easier for those people who wouldn't verify the key anyways to feel secure when they would be exactly as secure as they are now. That's what I mean by security theatre.
- tptacek 14y agoWhat you mean by security theater is that because some users don't verify binaries, it doesn't matter if anyone is able to verify binaries. You're trolling. Please go away.
- papsosouid 14y agoPlease, keep spamming "ur a troll!!1" like a child, it is very productive and adds a great deal to the discussions at HN. As I said, the 0.001% of the 0.001% who actually want to verify can already do so. Several mirrors have widely known ssh pubkeys.
- tptacek 14y agoAll the SSH pubkey tells you is that the attacker who owned up the distribution server didn't modify the SSH key.
- papsosouid 14y agoAll the PGP pubkey tells you is that the attacker who owned the build server didn't modify the PGP key.
- tptacek 14y agoNo. The person who owns the build server doesn't have the PGP key. SSH keys and PGP keys are not equivalent.
- papsosouid 14y agoHe doesn't need the PGP key, he tampered with the software before it was signed. I just phrased it that way in response to your absurd statement, a fact that should be painfully obvious. Theo is the guy in charge. He is the guy building the software. He would be the guy signing the software. When Bob owns the build server, he can trick Theo into signing his malicious binaries. Do you think Theo goes through each binary with a disassembler after he compiles them and ensures that the generated binaries are kosher? All PGP would get me is the ability to know Theo signed it. If it was tampered with during the build, or post-build, pre-signing, then I'm boned. That is the same situation we currently have. If Theo's machines get owned, we're boned. If they don't, we can easily verify that the sha-256 hash of the files on my hard drive, post download from wherever, match those that Theo built. At the end of the day, you are drawing a line about where to stop verifying and start trusting. The fact that you are download binaries as opposed to source means you are trusting the openbsd developers, not just personally, but in that they have secured access to the code and build process to prevent tampering. So then the only part you aren't trusting is the distribution mechanism, which ssh keys and sha-256 hashes allow you to verify, rather than needing to rely on trust.
- tptacek 14y ago"If Theo's machines get owned, we're boned" is not the scenario that signed releases addresses. No doubt you can concoct a scenario involving malicious robotic brain worms coercing Matthew Dempsky into committing a malicious system call. "PGP doesn't address that!", you'll say, "so it's all just theater". At the end of the day, you're simply wrong about the utility of release signing. You were mistaken about whether their security was compromised because signatures are fetched from the same location as the binaries (you were tripped up by the concept of "public key cryptography" there). And you were mistaken about the different threat models handled by SSH vs. PGP keys.