On Thu, Jan 25, 2018 at 11:55:58PM +0200, Alon Bar-Lev wrote: > I did not looked into the detailed implementation, however, please > make sure integrity check handles the same cases we have applied to > emerge-webrsync in the past, including: Gemato is the implementation of GLEP74/MetaManifest, which DOES explicitly address both of these concerns.
> 1. Fast forward only in time, this is required to avoid hacker to > redirect into older portage to install vulnerabilities that were > approved at that time. Replay attacks per #1 are addressed via TIMESTAMP field in MetaManifest. > 2. Content integrity, especially removal, as far as I understand, the > mechanism will not enable to detect authorized removal of content. I think you meant 'unauthorized' rather than 'authorized' here. It will detect files that are expected to exist but are missing. -- Robin Hugh Johnson Gentoo Linux: Dev, Infra Lead, Foundation Treasurer E-Mail : robb...@gentoo.org GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85 GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136
signature.asc
Description: Digital signature