Re: Bug#873122: HTTP Link to Keyring

Andreas Ronnquist <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <20170824233107.34cec5d5@debian-i7>
On Thu, 24 Aug 2017 19:53:59 +0200,
Hanno Böck<[email protected]> wrote:

>Package: www.debian.org
>
>When downloading a Debian CD there's a webpage explaining how to verify
>signatures:
>https://www.debian.org/CD/verify
>
>This recommends to check the signatures with the keys from the Debian
>GPG keyring. However that link is HTTP, pointing to:
>http://keyring.debian.org/
>
>It will immediately redirect to HTTPS, but an attacker could intercept
>that redirection and present a user with a malicious keyring instead.
>
>This makes the verification kinda pointless, as the keyring is
>delivered over a potentially insecure channel. The lack of HSTS on
>debian.org makes this particularly worriesome. Please change that link
>to HTTPS.
>

Thanks guys, this has been fixed in the CVS repository (including
translations) - It will be visible on the debian web pages when it has
been rebuilt (It rebuilds several times a day).

Thanks for your report!

-- Andreas Rönnquist
[email protected]
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.