www.delorie.com/archives/browse.cgi | search |
X-Recipient: | archive-cygwin AT delorie DOT com |
X-SWARE-Spam-Status: | No, hits=1.9 required=5.0 tests=BAYES_20,EXECUTABLE_URI,SARE_MSGID_LONG40 |
X-Spam-Check-By: | sourceware.org |
MIME-Version: | 1.0 |
In-Reply-To: | <66baf7b90905192003j1071dbe9vad179da6c74905fb@mail.gmail.com> |
References: | <66baf7b90905192002s7ab184d2le0f22e987875faad AT mail DOT gmail DOT com> <66baf7b90905192003j1071dbe9vad179da6c74905fb AT mail DOT gmail DOT com> |
Date: | Wed, 20 May 2009 00:11:35 -0700 |
Message-ID: | <66baf7b90905200011i465a3181g6158c37cacc68cb9@mail.gmail.com> |
Subject: | Re: Security Concern: setup.exe signature difficult to verify |
From: | Doug Bateman <doug AT dougbateman DOT net> |
To: | cygwin AT cygwin DOT com |
Mailing-List: | contact cygwin-help AT cygwin DOT com; run by ezmlm |
List-Id: | <cygwin.cygwin.com> |
List-Unsubscribe: | <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com> |
List-Subscribe: | <mailto:cygwin-subscribe AT cygwin DOT com> |
List-Archive: | <http://sourceware.org/ml/cygwin/> |
List-Post: | <mailto:cygwin AT cygwin DOT com> |
List-Help: | <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs> |
Sender: | cygwin-owner AT cygwin DOT com |
Mail-Followup-To: | cygwin AT cygwin DOT com |
Delivered-To: | mailing list cygwin AT cygwin DOT com |
Greg Chicares Wrote: > Here's a native msw binary: > ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.9.exe Thanks for the response Greg. This still raises 2 concerns: 1) If this method is the official cygwin authenticity verification procedure, it should be well documented on the website, as the process is non-trivial. 2) The gnupg-w32cli-1.4.9.exe itself also isn't signed. So we still have the bootstrapping problem. Bottom line, the install procedure is still insecure and vulnerable to attack until a pervasive authentication mechanism is used (either signed windows executable or SSL download with a verifiable cert). With organized and highly sophisticated attackers becoming even more wide spread (often backed by organized crime or other well funded agencies), security is important, especially for a project as prestigious and important as Cygwin. Of course, I'll mention this to the gnupg.org people too, as they have the same problem. Thanks for the response. Best Regards, Doug -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/
webmaster | delorie software privacy |
Copyright © 2019 by DJ Delorie | Updated Jul 2019 |