Re: dpkg MD5
Jeremy Stanley <[email protected]> Fri, 8 Nov 2024 17:22:36 +0000
| Newsgroups | gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <[email protected]> |
On 2024-11-08 15:41:25 +0000 (+0000), Jeremy Stanley wrote: [...] > Now grab a package file like > https://deb.debian.org/debian/pool/main/o/openssh/ssh_9.9p1-3_all.deb > and unpack it (dpkg-deb ssh_9.9p1-3_all.deb foo) [...] Hopefully obvious, but that should have been `dpkg-deb -R ...` instead, sorry! As always, check example commands against a proper manpage before you run them. ;) On 2024-11-08 16:52:19 +0100 (+0100), SZÉPE Viktor wrote: [...] > I am a frequent debsums runner. debsums alerts you when a file > from a Debian package has changed. Please keep those MD5-s. Yes, you completely snipped the part where I suggested that the MD5 checksums are used by the debsums utility, and are useful for spotting on-disk changes to files after installation (mainly in cases of accidental corruption, e.g. after a fsck repair or something). I haven't seen anyone suggest removing them, and I'm not suggesting it either. Obviously running a tool locally to check a local copy of checksums for locally stored files isn't much of a security feature though, as an attacker who is able to alter those files probably also had sufficient access to alter the list of checksums, the checking tool, or anything else they desired anyway. This is not a fault of using MD5, and replacing it with a different algorithm wouldn't solve that regardless. -- Jeremy Stanley
signature.asc
(application/pgp-signature, 963 B)
-----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmcuSNZfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3 QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ WClsIRAAk0eOGUcfYAEjq80FzRHIQdWKL4jEDLJIoGoDV9WejzH+sDyPPbJ8jVr/ F3cYlHnAhxg3tN0Mi29X1e0gLatOyf28YfxZOK1Rey0ebeHN+klH96hSqJ4Tsa+Y U7Nvor6eZmNuenHenPJ2Ys1Rb0JIPgdEj7VahI7O4D7vGwTccy5ThA1uVdImMhVG NHixjGxHyKVbQBD0XJv45ow1QZjHNai5eLrBzfBfYa7+OftG3BfVvZoDRdvIKPfF f4VYYmxHAQW7w4VncoafpeG+6KvGR09akDewZvpHKBjuMtzwWy0MP9RlAeabAQvk N+Mc1kGu+pAcjgVkPAB+Ld/yYMiUOkJd/sxQe/IAaYITgFqFFj6p1tMLnQFrEbG6 QPmij+TU2wI+G2BKuiUJrV5bZ4MwNS3wwhD0S+rJOtc+AEIoOnTguvOgQ4WyuGJV bZ1eUPO0nUWDkupDQn9LXtyiPtCjJKXctUQExsPxpDPEXgY+HqYwlf8TCl3XCbJL VHrQ/CTJGo7pTaUvTTyKFOkQ6xu/SabbBzVo0a8ASEeP4JhL2XbpGctO1T0lkiHw Q6N+AwaI7W9tQ8o+oQaxppcyiyMWxiG3WAhzwhNZdiZsiYiscyo5SAeHOtv/zR+Y ij3cckm3YgEu6Oo3B7sk3eFpBnebQynV6nhtouD5BZWbPSs2Ceg= =9NAG -----END PGP SIGNATURE-----