Hashes,File protection,etc

From: Dave Aitel (daveat_private)
Date: Mon Oct 14 2002 - 11:59:14 PDT

  • Next message: Dave Aitel: "Re: Hashes,File protection,etc"

    On Mon, 2002-10-14 at 14:40, Dan Kaminsky wrote:
    
    > >  
    > >
    > For remotely computed data / hashes, you can't -- thus the folly of 
    > trusting MD5 hashes on critical files downloaded off of untrusted 
    > servers.  If somebody can modify the tarball, they can probably modify 
    > the hash too.
    
    Well, not always, if there is a semi-trusted third party or two - see
    http://www.immunitysec.com/hashdb.html for one implementation of this
    sort of thing. 
    
    -- 
    Dave Aitel <daveat_private>
    Immunity, Inc
    
    
    



    This archive was generated by hypermail 2b30 : Mon Oct 14 2002 - 12:34:21 PDT