• I’m probably having a brainfart (watched the video during insomnia), but re: the section 12m 10s into the video, can someone please clarify why “the instructions are dangerously wrong”?

    I understand it relates to the earlier demo in which those instructions gave the illusion of “verifying” an ISO that was in fact malicious. But:

    • why did those instructions fail to genuinely verify the ISO?
    • what would the correct instructions have been?
    • tribut ( tribut@infosec.pub ) 
      link
      fedilink
      arrow-up
      2
      ·
      3 days ago

      Cleatext signing (having the signature and data in the same file) is broken in many ways. It is possible to put unsigned data at the top of the file in a way that sha256sum will use it. Watch the 39c3 GPG talk if your interested in the gory details.

      The solution is to use detached signatures (checksum.txt and checksum.txt.gpg to verify that). This makes sure that all of checksum.txt is actually covered by the signature.