Re: CLiki and ALU Wiki sites massively spammed
- From: "Nathan Baum" <nathan_baum@xxxxxxxxxxxxxx>
- Date: 23 Jan 2006 13:54:17 -0800
Christophe Rhodes wrote:
> "Nathan Baum" <nathan_baum@xxxxxxxxxxxxxx> writes:
>
> > Christophe Rhodes wrote:
> >> Right, which is why asdf-install does not trust the wiki. Instead, it
> >> asks you to trust library authors.
> >
> > It asks you to trust _Wiki authors_, who may not be the library
> > authors.
>
> No, it doesn't.
It does, for the reason you accept: signatureless packages can be
trivially spoofed. It also requires you trust Wiki authors not to make
packages unavailable, something which could be just as dangerous as
making a fake package if your current version has known exploits.
> >> With a wiki-like scheme, you have to trust
> >> * the individual library authors
> >> and no-one else.
> >
> > Assuming that the host they're using is safe from compromise, that your
> > DNS hasn't been hit by spoofing, and any of a number of other
> > scenarios.
>
> No. If my DNS has been hit by spoofing or the host they use is
> compromised, and I download a package that is signed by someone not in
> my trust ring (or not signed at all), then the system will have done
> its job: it will have alerted me to the fact that a package might not
> be what it seems. It is true that this relies on authors not being
> terribly stupid with their gpg private keys, and also on some minimal
> physical connection with the PGP Web of Trust, but it in no way relies
> on the integrity of any internet host.
You're right about the DNS spoofing, but not necessarily right about
the compromised host. Because of the way the Wiki system works, content
is not (necessarily) hosted by a third party. If I host a package on my
personal host and make it available via CLiki, and then my host is
compromised then it is possible that the attacker could sign a
corrupted package with my key.
> Christophe
.
- Follow-Ups:
- Re: CLiki and ALU Wiki sites massively spammed
- From: Christophe Rhodes
- Re: CLiki and ALU Wiki sites massively spammed
- References:
- CLiki and ALU Wiki sites massively spammed
- From: Paolo Amoroso
- Re: CLiki and ALU Wiki sites massively spammed
- From: Christophe Rhodes
- Re: CLiki and ALU Wiki sites massively spammed
- From: Bill Atkins
- Re: CLiki and ALU Wiki sites massively spammed
- From: Christophe Rhodes
- Re: CLiki and ALU Wiki sites massively spammed
- From: Nathan Baum
- Re: CLiki and ALU Wiki sites massively spammed
- From: Christophe Rhodes
- CLiki and ALU Wiki sites massively spammed
- Prev by Date: Re: PCL in the Jolt Awards finals!
- Next by Date: Re: PCL in the Jolt Awards finals!
- Previous by thread: Re: CLiki and ALU Wiki sites massively spammed
- Next by thread: Re: CLiki and ALU Wiki sites massively spammed
- Index(es):
Relevant Pages
|
|