Re: kernel.org status: establishing a PGP web of trust

From: Ted Ts'o
Date: Wed Oct 05 2011 - 19:47:38 EST


On Thu, Oct 06, 2011 at 12:25:26AM +0300, Adrian Bunk wrote:
>
> Had debsums told me that /bin/bash was modified I would have been quite
> convinced.
>

Keep in mind that debsums is trivially easy to circument. That just
checks against an md5 checksum stored in a text file in
/var/lib/dpkg/info/*.md5sums. If someone modified /bin/bash it would
easy enough for them to modify the relevant md5sums file.

- Ted
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/