From owner-freebsd-questions@FreeBSD.ORG Sat Jan 3 01:38:35 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id BCCFD106564A for ; Sat, 3 Jan 2009 01:38:35 +0000 (UTC) (envelope-from rwmaillists@googlemail.com) Received: from mail-ew0-f21.google.com (mail-ew0-f21.google.com [209.85.219.21]) by mx1.freebsd.org (Postfix) with ESMTP id 500308FC16 for ; Sat, 3 Jan 2009 01:38:35 +0000 (UTC) (envelope-from rwmaillists@googlemail.com) Received: by ewy14 with SMTP id 14so7869852ewy.19 for ; Fri, 02 Jan 2009 17:38:34 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlemail.com; s=gamma; h=domainkey-signature:received:received:date:from:to:subject :message-id:in-reply-to:references:x-mailer:mime-version :content-type:content-transfer-encoding; bh=D3qn2r9gaVbAD948sDkWYtcqAxYD0toRmcGZpCrdi/0=; b=VMoKKV9EViZj9LNdzRIbO2UC4M70YfEdZp9WSFevYIipqmQGzNu9u1+k0KgIz/Z56u RCPGCaUWyR1towfdKhu/RWwTqwn9pu6F42YeshgCUvrR52PZulVCsDXBSy6sb5z9auqj 3FRUK7EbM0zU6mF6KxFvmneodz1sYhMwUAyUc= DomainKey-Signature: a=rsa-sha1; c=nofws; d=googlemail.com; s=gamma; h=date:from:to:subject:message-id:in-reply-to:references:x-mailer :mime-version:content-type:content-transfer-encoding; b=Klk4oInDvegyx4w/ZqLYkadMFOFqosl8v4CWCp0uTDf/qKlmPeDn7QF1vQqywPO95p JbHE/FBgZrOZSGRfA2qCkrxiGivgKFV81kicg79hykaYGKLgTn+bjH2cdZMwXU87O0x3 rPf0/fjMA+tZFlFx1dGSI3JSeBDvts4QzuGp4= Received: by 10.210.61.8 with SMTP id j8mr21639401eba.45.1230946714139; Fri, 02 Jan 2009 17:38:34 -0800 (PST) Received: from gumby.homeunix.com (bb-87-81-140-128.ukonline.co.uk [87.81.140.128]) by mx.google.com with ESMTPS id b30sm6511257ika.7.2009.01.02.17.38.30 (version=SSLv3 cipher=RC4-MD5); Fri, 02 Jan 2009 17:38:33 -0800 (PST) Date: Sat, 3 Jan 2009 01:38:25 +0000 From: RW To: freebsd-questions@freebsd.org Message-ID: <20090103013825.18910bf5@gumby.homeunix.com> In-Reply-To: <495E4F24.80209@unsane.co.uk> References: <20090102164412.GA1258@phenom.cordula.ws> <495E4F24.80209@unsane.co.uk> X-Mailer: Claws Mail 3.5.0 (GTK+ 2.12.11; i386-portbld-freebsd7.0) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: Re: Foiling MITM attacks on source and ports trees X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 03 Jan 2009 01:38:36 -0000 On Fri, 02 Jan 2009 17:30:12 +0000 Vincent Hoffman wrote: > Admittedly this doesn't give a file by file checksum That's not really a problem, it's no easier to create a collision in a .gz file than a patch file. The more substantial weakness is that the key is verified against a hash stored on the original installation media. If someone went to the trouble of diverting dns or routing to create a fake FreeBSD site they would presumably make it self-consistent down to the ISO checksums.