Signed hashes of security updates
Vaibhav Gavane <[email protected]> Tue, 23 Jun 2015 13:52:10 +0000
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <CA+K6jVkEF3T94MSn0-sN_4yOuu0=3syaN7osFBL4YPcHbS3ODw@mail.gmail.com> |
Hello, It seems that the security updates (i.e. the builds at, say, nyftp.netbsd.org/pub/NetBSD-daily/netbsd-6-1/) are provided without any *signed* hashes. Am I missing/unaware of their location, if they exist? If not, then the security updates are themselves vulnerable to MITM attacks. The server (nyftp.netbsd.org) is neither accessible with HTTPS, nor accessible with guest/anonymous SFTP. Vaibhav Gavane