Re: status: establishing a PGP web of trust

From: Ted Ts'o
Date: Wed Oct 05 2011 - 19:47:38 EST

On Thu, Oct 06, 2011 at 12:25:26AM +0300, Adrian Bunk wrote:
> Had debsums told me that /bin/bash was modified I would have been quite
> convinced.

Keep in mind that debsums is trivially easy to circument. That just
checks against an md5 checksum stored in a text file in
/var/lib/dpkg/info/*.md5sums. If someone modified /bin/bash it would
easy enough for them to modify the relevant md5sums file.

- Ted
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at
Please read the FAQ at