delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2009/05/20/03:12:05

X-Recipient: archive-cygwin AT delorie DOT com
X-SWARE-Spam-Status: No, hits=1.9 required=5.0 tests=BAYES_20,EXECUTABLE_URI,SARE_MSGID_LONG40
X-Spam-Check-By: sourceware.org
MIME-Version: 1.0
In-Reply-To: <66baf7b90905192003j1071dbe9vad179da6c74905fb@mail.gmail.com>
References: <66baf7b90905192002s7ab184d2le0f22e987875faad AT mail DOT gmail DOT com> <66baf7b90905192003j1071dbe9vad179da6c74905fb AT mail DOT gmail DOT com>
Date: Wed, 20 May 2009 00:11:35 -0700
Message-ID: <66baf7b90905200011i465a3181g6158c37cacc68cb9@mail.gmail.com>
Subject: Re: Security Concern: setup.exe signature difficult to verify
From: Doug Bateman <doug AT dougbateman DOT net>
To: cygwin AT cygwin DOT com
Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie DOT com AT cygwin DOT com>
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com

Greg Chicares Wrote:
> Here's a native msw binary:
>  ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.9.exe

Thanks for the response Greg.  This still raises 2 concerns:
1) If this method is the official cygwin authenticity verification
procedure, it should be well documented on the website, as the process
is non-trivial.
2) The gnupg-w32cli-1.4.9.exe itself also isn't signed.  So we still
have the bootstrapping problem.

Bottom line, the install procedure is still insecure and vulnerable to
attack until a pervasive authentication mechanism is used (either
signed windows executable or SSL download with a verifiable cert).
With organized and highly sophisticated attackers becoming even more
wide spread (often backed by organized crime or other well funded
agencies), security is important, especially for a project as
prestigious and important as Cygwin.

Of course, I'll mention this to the gnupg.org people too, as they have
the same problem.

Thanks for the response.

Best Regards,
Doug

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019