tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Signed hashes of security updates



Hello,

It seems that the security updates (i.e. the builds at, say,
nyftp.netbsd.org/pub/NetBSD-daily/netbsd-6-1/) are provided without
any *signed* hashes.

Am I missing/unaware of their location, if they exist?

If not, then the security updates are themselves vulnerable to MITM
attacks. The server (nyftp.netbsd.org) is neither accessible with
HTTPS, nor accessible with guest/anonymous SFTP.

Vaibhav Gavane


Home | Main Index | Thread Index | Old Index