Signed hashes of security updates

Vaibhav Gavane <[email protected]> Tue, 23 Jun 2015 13:52:10 +0000
Newsgroups gmane.os.netbsd.devel.security
Message-ID <CA+K6jVkEF3T94MSn0-sN_4yOuu0=3syaN7osFBL4YPcHbS3ODw@mail.gmail.com>
Hello,

It seems that the security updates (i.e. the builds at, say,
nyftp.netbsd.org/pub/NetBSD-daily/netbsd-6-1/) are provided without
any *signed* hashes.

Am I missing/unaware of their location, if they exist?

If not, then the security updates are themselves vulnerable to MITM
attacks. The server (nyftp.netbsd.org) is neither accessible with
HTTPS, nor accessible with guest/anonymous SFTP.

Vaibhav Gavane