Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution
Paul Roberts <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 10 Oct 2002, Sam Halliday wrote: > On 10 Oct 2002 12:10:03 -0600 Ken Dyke <[email protected]> > wrote: > > I know how. And now it is in the mail archives if it wasn't before. > > Files can also be checked with > > md5sum foo.bar > > then check the hash against the published md5 signature. The md5 > > checksum for gnupg can be found on http://www.gnupg.org/download.html > > but this is insecure... if the ftp site has been hacked, chances are > that the md5sum has been also... only trust md5sums which have been > signed. This is completely true... Thankfully the guys who are doing the hacks are apparently just going for the people too dim to check even the md5sums, since these very people are even less likely to notice anything unusual going on in their system. ...or at least, it's what they've been doing _so far_. The real solution to this is to start sending emails to the maintainers of every package you build that does _not_ have a published public key and signature file, and ask them to start signing their releases. Ask them to pester anyone else they know who publishes code to do the same thing and for them to sign each other's keys. The annoying thing is that the biggest group of people who could do something about this sort of thing (namely, the Gnome developers, since they've a positively _massive_ community going) have just been _lazy_ about it. ...but a continuing flood of emails may well change this. People using Mozilla or Evolution for email really have no excuse for not having their own GPG keys now... -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message