OT-Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution

Ken Dyke <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <1034276929.12883.23.camel@FatBoy>
On Thu, 2002-10-10 at 12:21, Sam Halliday wrote:
> On 10 Oct 2002 12:10:03 -0600 Ken Dyke <[email protected]>
> wrote:
> > I know how.  And now it is in the mail archives if it wasn't before.
> > Files can also be checked with
> > md5sum foo.bar
> > then check the hash against the published md5 signature.  The md5
> > checksum for gnupg can be found on http://www.gnupg.org/download.html
> 
> but this is insecure... if the ftp site has been hacked, chances are
> that the md5sum has been also... only trust md5sums which have been
> signed.

You are in a non-terminating loop as regards gnupg.  The gnupg.org http
server and the ftp server are different machines (I believe).  They are
definitely not the same as the mirrors.  IIRC trojan packages are
usually injected into a mirror.

Anyway, as regards gnupg the Gordian Knot must be sliced.  Taking this
leap and recognizing it for what it is, gnupg can then be used to verify
other packages.  If at some point in the future, it is revealed that the
gnupg package was in fact compromised, one gets to start over from the
beginning.

Another option for cutting this Knot is to audit the gnupg package
yourself.  :-)

-- 
I think, therefore, ken_i_m
Chief Gadgeteer,
Elegant Innovations

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.