, 2002-08-07
The OpenSSH backdoor demonstrates that the community must get pragmatic about package verification, and fast.
Expand all |
Post comment
Time Time to Grow UP? NO! Time to quit acting like children! There is a difference.
2002-08-09
Axe-2-Grind
Axe-2-Grind

Note that FreeBSD only caught it because of its out-of-band signatures: had they relied on MD5sums in the OpenSSH FTP tree it would have been a lost cause. Most packages have their MD5sums distributed in the latter fashion; even the Ports tree has a limited number of apps with external MD5sums (ie, not everything is in the Ports tree)
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/101/16100#16100