X-Recipient: archive-cygwin AT delorie DOT com X-SWARE-Spam-Status: No, hits=1.9 required=5.0 tests=BAYES_20,EXECUTABLE_URI,SARE_MSGID_LONG40 X-Spam-Check-By: sourceware.org MIME-Version: 1.0 In-Reply-To: <66baf7b90905192003j1071dbe9vad179da6c74905fb@mail.gmail.com> References: <66baf7b90905192002s7ab184d2le0f22e987875faad AT mail DOT gmail DOT com> <66baf7b90905192003j1071dbe9vad179da6c74905fb AT mail DOT gmail DOT com> Date: Wed, 20 May 2009 00:11:35 -0700 Message-ID: <66baf7b90905200011i465a3181g6158c37cacc68cb9@mail.gmail.com> Subject: Re: Security Concern: setup.exe signature difficult to verify From: Doug Bateman To: cygwin AT cygwin DOT com Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com Greg Chicares Wrote: > Here's a native msw binary: > ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.9.exe Thanks for the response Greg. This still raises 2 concerns: 1) If this method is the official cygwin authenticity verification procedure, it should be well documented on the website, as the process is non-trivial. 2) The gnupg-w32cli-1.4.9.exe itself also isn't signed. So we still have the bootstrapping problem. Bottom line, the install procedure is still insecure and vulnerable to attack until a pervasive authentication mechanism is used (either signed windows executable or SSL download with a verifiable cert). With organized and highly sophisticated attackers becoming even more wide spread (often backed by organized crime or other well funded agencies), security is important, especially for a project as prestigious and important as Cygwin. Of course, I'll mention this to the gnupg.org people too, as they have the same problem. Thanks for the response. Best Regards, Doug -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/