Bug#863317: apt: susceptible to replay attacks

2017-06-02 Thread David Kalnischkies
On Tue, May 30, 2017 at 01:29:33AM +0200, Jakub Wilk wrote: > * David Kalnischkies , 2017-05-28, 10:35: > > > > Unfortunately, this protection is ineffective. All the attacker > > > > needs to do to hide security updates is to replace all the files > > > > from

Bug#863317: apt: susceptible to replay attacks

2017-05-29 Thread Jakub Wilk
* David Kalnischkies , 2017-05-28, 10:35: Unfortunately, this protection is ineffective. All the attacker needs to do to hide security updates is to replace all the files from http://security.debian.org/dists/$DIST/updates/ with the ones from

Bug#863317: apt: susceptible to replay attacks

2017-05-28 Thread David Kalnischkies
On Thu, May 25, 2017 at 02:10:11PM +0200, Julian Andres Klode wrote: > On Thu, May 25, 2017 at 01:30:13PM +0200, Jakub Wilk wrote: > > Unfortunately, this protection is ineffective. All the attacker needs to do > > to hide security updates is to replace all the files from > >

Bug#863317: apt: susceptible to replay attacks

2017-05-25 Thread Julian Andres Klode
On Thu, May 25, 2017 at 01:30:13PM +0200, Jakub Wilk wrote: > Package: apt > Version: 1.0.9.8.4 > Tags: security > > Nearly a decade ago, Valid-Until fields were added to Release files (bug > #499897). The primary motivation for this was to protect from a > man-in-the-middle adversary from

Bug#863317: apt: susceptible to replay attacks

2017-05-25 Thread Jakub Wilk
Package: apt Version: 1.0.9.8.4 Tags: security Nearly a decade ago, Valid-Until fields were added to Release files (bug #499897). The primary motivation for this was to protect from a man-in-the-middle adversary from serving an outdated copy of the security mirror. Unfortunately, this