3 ms·
Interesting read. On thing i do not understand is why software updates/packages are still not cryptographically signed. It's a common thing on Linux. Notepad++
by ushi 13y ago
Interesting read. On thing i do not understand is why software updates/packages are still not cryptographically signed. It's a common thing on Linux. Notepad++ provides checksums[0] for their packages - so (i assume) they are actually aware of the problem.
[0] http://sourceforge.net/p/notepad-plus/discussion/1290588 http://sourceforge.net/p/notepad-plus/discussion/1290588
- aaronem 13y agoSure, but if you're MITMing DNS, you just serve a copy of the Notepad++ download page (or whatever) whose listed checksum matches that of your backdoored executable, so that's not a problem in this scenario.
- ushi 13y agoThats exactly what i mean - checksums are useless in this scenario. They should have been signed with a key your computer knows. (Retrieved before the first install)
- aaronem 13y agoOh, I see what you mean. I wish I saw a way for that to happen in the Windows ecosystem, although I suppose the "Windows Store" might drive evolution in that direction.
- maxerickson 13y agoIt does exist: http://blogs.msdn.com/b/ieinternals/archive/2011/03/22/authenticode-code-signing-for-developers-for-file-downloads-building-smartscreen-application-reputation.aspx http://blogs.msdn.com/b/ieinternals/archive/2011/03/22/authe... The problem is that it doesn't help users any, the only way to stop them is to take control of the system away and it doesn't go that far.
- ambrop7 13y agoThey're not useless if you rely on Google for verification (see my top level comment).
- meowface 13y agoMany applications will require signed updates, but considering how much software the average person has on their computer (especially a tech geek), odds are at least one will upgrade over regular HTTP. And that's all an attacker needs.
- deleted 13y ago[deleted]
- revelation 13y agoIt's common on Linux because they use package managers where you only have to implement that functionality once. Every PoS app on Windows and OSX has its own update process, which mostly is just downloading and running the new setup binary. This happens even with software where you would think the manufacturer is aware of this kind of problem. 1Password downloaded updates over HTTP for a long time, then switched to HTTPS and failed to check certificates. When they finally started to check if binaries are signed (Windows provides for that), they didn't change keys so you could downgrade to a previous version that didn't. That is just one application.
- kalleboo 13y ago> Every PoS app on Windows and OSX has its own update process, which mostly is just downloading and running the new setup binary. Most OS X apps use either the Mac App Store, which signs everything, or Sparkle[0], which last time I used it made it really hard to use it without signing things. It's only stuff from big vendors like Adobe and Microsoft who do custom stuff you can't really trust. [0] http://sparkle.andymatuschak.org http://sparkle.andymatuschak.org