oss-sec mailing list archives
Re: CVE for Kali Linux
From: Daniel Micay <danielmicay () gmail com>
Date: Sun, 22 Mar 2015 08:05:27 -0400
On 22/03/15 07:06 AM, Florian Weimer wrote:
* Daniel Micay:Is there actually a way for a Windows user to obtain it securely?I believe there are ideological objections to using an Authenticode signature (same as with Tor).
Tor provides their download via HTTPS from the same domain and has both HSTS preloading and HPKP. They provide a link to a GPG signature for the tarball too, but that doesn't help most users unless their distro is using it in package sources. AFAICT they plan on doing Authenticode signing, but they're doing a good job without it. The problem with these Linux distro downloads is that it's consistently done via http. That's fine for packages because package signing takes care of it. It's fine if the download is done in a way that results in verification like a torrent, but otherwise the user needs to manually verify a hash or signature and that's rarely going to happen. It's 2015 and Debian shouldn't have an HTTP download link for the ISO on their front page :P.
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- CVE for Kali Linux Kurt Seifried (Mar 21)
- Re: CVE for Kali Linux Justin Steven (Mar 21)
- Re: CVE for Kali Linux Kurt Seifried (Mar 21)
- Re: CVE for Kali Linux Daniel Micay (Mar 21)
- Re: CVE for Kali Linux Russ Allbery (Mar 21)
- Re: CVE for Kali Linux Daniel Micay (Mar 21)
- Re: CVE for Kali Linux Daniel Micay (Mar 21)
- Re: CVE for Kali Linux Florian Weimer (Mar 22)
- Re: CVE for Kali Linux Daniel Micay (Mar 22)
- Re: CVE for Kali Linux Kurt Seifried (Mar 21)
- Re: CVE for Kali Linux Amos Jeffries (Mar 22)
- Re: CVE for Kali Linux Daniel Micay (Mar 22)
- Re: CVE for Kali Linux Justin Steven (Mar 21)
- Re: CVE for Kali Linux Michael Samuel (Mar 21)
- Re: CVE for Kali Linux Florian Weimer (Mar 22)
- Re: CVE for Kali Linux Kurt Seifried (Mar 22)
- Re: CVE for Kali Linux Jeremy Stanley (Mar 22)
- Re: CVE for Kali Linux Kurt Seifried (Mar 22)
- Re: CVE for Kali Linux David A. Wheeler (Mar 22)
- Re: CVE for Kali Linux Solar Designer (Mar 22)
- Re: CVE for Kali Linux Solar Designer (Mar 22)