Re: GNU software compromised : Cert Advisory

From: Jem Berkes (jb_at_users.pc9.org)
Date: 08/15/03


Date: 15 Aug 2003 05:39:40 GMT


     
> Am I understanding this correctly? All anyone has to do to evade this
> cracker's work is to check the md5 sums?

I think what's happening is: the FSF already has known good md5sums for
most of the files on their FTP site. By comparing the current files' hashes
against the known good lists, they can confirm that those files have not
been tampered with.

The FSF is also seeking md5sums for files that they _did_not_ have records
of. They are unsure whether these files have been modified.

So this business about md5 sums is the FSF verifying the integrity of their
previously compromised FTP site, to make sure nothing was altered.



Relevant Pages

  • Re: GNU software compromised : Cert Advisory
    ... The FSF is also seeking md5sums for files that they _did_not_ have records ... So this business about md5 sums is the FSF verifying the integrity of their ... previously compromised FTP site, to make sure nothing was altered. ...
    (comp.os.linux.setup)
  • Re: GNU software compromised : Cert Advisory
    ... The FSF is also seeking md5sums for files that they _did_not_ have records ... So this business about md5 sums is the FSF verifying the integrity of their ... previously compromised FTP site, to make sure nothing was altered. ...
    (comp.os.linux)
  • Re: GNU software compromised : Cert Advisory
    ... The FSF is also seeking md5sums for files that they _did_not_ have records ... So this business about md5 sums is the FSF verifying the integrity of their ... previously compromised FTP site, to make sure nothing was altered. ...
    (comp.os.linux.security)
  • Re: Problem with building the DVD iso image for 10.1
    ... at the end it is calculating the md5 sums, ... statement about the iso being saved. ... so a generic md5sum is pretty useless. ... If you want to do md5sums un whatever you put on your FTP site, ...
    (alt.os.linux.suse)