On Wed, Dec 05, 2007, STeve Andre' wrote:
> Yes, one can dismiss the "benefits". Think about what an MD5 (or any
> Answer: it doesn't.
Wrong.
If someone cracks a website, then he can put up a modified binary
and a modified MD5 checksum. Creating a (digital) signature (with
the right key) is significantly more complex.
Using CDs to distribute the code make the attack of course rather
complicated.
Someone actually did the former with sendmail.org (to distribute a
version of sendmail with a backdoor). The problem was only noted
because users checked the (digital) signature.
| Andrew Morton | -mm merge plans for 2.6.23 |
| Rafael J. Wysocki | [Bug #11207] VolanoMark regression with 2.6.27-rc1 |
| Zhang, Yanmin | AIM7 40% regression with 2.6.26-rc1 |
| Con Kolivas | [PATCH][RSDL-mm 0/7] RSDL cpu scheduler for 2.6.21-rc3-mm2 |
git: | |
| Gregory Haskins | [RFC PATCH 03/17] vbus: add connection-client helper infrastructure |
| David Woodhouse | [PATCH 03/30] solos: FPGA and firmware update support. |
| Natalie Protasevich | [BUG] New Kernel Bugs |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
