X-Recipient: archive-cygwin@delorie.com
X-SWARE-Spam-Status: No, hits=1.9 required=5.0 	tests=BAYES_20,EXECUTABLE_URI,SARE_MSGID_LONG40
X-Spam-Check-By: sourceware.org
MIME-Version: 1.0
In-Reply-To: <66baf7b90905192003j1071dbe9vad179da6c74905fb@mail.gmail.com>
References: <66baf7b90905192002s7ab184d2le0f22e987875faad@mail.gmail.com> 	 <66baf7b90905192003j1071dbe9vad179da6c74905fb@mail.gmail.com>
Date: Wed, 20 May 2009 00:11:35 -0700
Message-ID: <66baf7b90905200011i465a3181g6158c37cacc68cb9@mail.gmail.com>
Subject: Re: Security Concern: setup.exe signature difficult to verify
From: Doug Bateman <doug@dougbateman.net>
To: cygwin@cygwin.com
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Mailing-List: contact cygwin-help@cygwin.com; run by ezmlm
Precedence: bulk
List-Id: <cygwin.cygwin.com>
List-Unsubscribe: <mailto:cygwin-unsubscribe-archive-cygwin=delorie.com@cygwin.com>
List-Subscribe: <mailto:cygwin-subscribe@cygwin.com>
List-Archive: <http://sourceware.org/ml/cygwin/>
List-Post: <mailto:cygwin@cygwin.com>
List-Help: <mailto:cygwin-help@cygwin.com>, <http://sourceware.org/ml/#faqs>
Sender: cygwin-owner@cygwin.com
Mail-Followup-To: cygwin@cygwin.com
Delivered-To: mailing list cygwin@cygwin.com

Greg Chicares Wrote:
> Here's a native msw binary:
>  ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.9.exe

Thanks for the response Greg.  This still raises 2 concerns:
1) If this method is the official cygwin authenticity verification
procedure, it should be well documented on the website, as the process
is non-trivial.
2) The gnupg-w32cli-1.4.9.exe itself also isn't signed.  So we still
have the bootstrapping problem.

Bottom line, the install procedure is still insecure and vulnerable to
attack until a pervasive authentication mechanism is used (either
signed windows executable or SSL download with a verifiable cert).
With organized and highly sophisticated attackers becoming even more
wide spread (often backed by organized crime or other well funded
agencies), security is important, especially for a project as
prestigious and important as Cygwin.

Of course, I'll mention this to the gnupg.org people too, as they have
the same problem.

Thanks for the response.

Best Regards,
Doug

--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

