Re: Debsums fun

2008-10-27 Thread Mark Allums
Martin Ågren wrote: 2008/10/27 Mark Allums <[EMAIL PROTECTED]>: On 2008-10-27 08:24 +0100, David Baron wrote: The newest debsums from Sid can do a daily check for md5 disagreement. Useful for security? [...] MD5s are not useful for security purposes any more. They are too easy to duplicate

Re: Debsums fun

2008-10-27 Thread Martin Ågren
2008/10/27 Mark Allums <[EMAIL PROTECTED]>: >> On 2008-10-27 08:24 +0100, David Baron wrote: >> >>> The newest debsums from Sid can do a daily check for md5 disagreement. >>> Useful for security? >> [...] > MD5s are not useful for security purposes any more. They are too easy to > duplicate with a

Re: Debsums fun

2008-10-27 Thread Mark Allums
Sven Joachim wrote: On 2008-10-27 08:24 +0100, David Baron wrote: The newest debsums from Sid can do a daily check for md5 disagreement. Useful for security? Not really. An attacker that can modify system files can and will also update the md5sums under /var/lib/dpkg/info. Besides, scanning

Re: Debsums fun

2008-10-27 Thread Sven Joachim
On 2008-10-27 08:24 +0100, David Baron wrote: > The newest debsums from Sid can do a daily check for md5 disagreement. Useful > for security? Not really. An attacker that can modify system files can and will also update the md5sums under /var/lib/dpkg/info. Besides, scanning each and every ins