Please bear with my dumb ass. if validating a certificate / signature is risking an RCE, does that essentially make this a planet-wide potential supply chain hack (wherever gnupg is used, at least?)
Follow up: I suppose the verification could be done in a container?
I’m probably having a brainfart (watched the video during insomnia), but re: the section 12m 10s into the video, can someone please clarify why “the instructions are dangerously wrong”?
I understand it relates to the earlier demo in which those instructions gave the illusion of “verifying” an ISO that was in fact malicious. But:
- why did those instructions fail to genuinely verify the ISO?
- what would the correct instructions have been?
Cleatext signing (having the signature and data in the same file) is broken in many ways. It is possible to put unsigned data at the top of the file in a way that sha256sum will use it. Watch the 39c3 GPG talk if your interested in the gory details.
The solution is to use detached signatures (checksum.txt and checksum.txt.gpg to verify that). This makes sure that all of checksum.txt is actually covered by the signature.
cc @modem_down@thebrainbin.org
or, binary signatures, [which I prefer: compressionable], as textfiles are insecure formats.I prefer a headed, mided, and tailed verification, similar to MPEG keyframing, for constant stream verification.
Lexi Groves is quoting Fedora’s own mailing list irt social engineering. Both Fedora’s instructions are wrong, and the method to properly verify ISO, that to be brutal, should have been outdated decades ago, is “dangerously wrong.” It’s a nice gibe.




