Vulnerability Development mailing list archives

Hashes,File protection,etc


From: Dave Aitel <dave () immunitysec com>
Date: 14 Oct 2002 14:59:14 -0400



On Mon, 2002-10-14 at 14:40, Dan Kaminsky wrote:

 

For remotely computed data / hashes, you can't -- thus the folly of 
trusting MD5 hashes on critical files downloaded off of untrusted 
servers.  If somebody can modify the tarball, they can probably modify 
the hash too.

Well, not always, if there is a semi-trusted third party or two - see
http://www.immunitysec.com/hashdb.html for one implementation of this
sort of thing. 

-- 
Dave Aitel <dave () immunitysec com>
Immunity, Inc

Attachment: signature.asc
Description: This is a digitally signed message part


Current thread: