Debian: "We don't need to use HTTPS, we sign our packages! Check out whydoesaptnotusehttps[.]com!"
https://lists.debian.org/debian-security-announce/2019/msg00010.html …
https://justi.cz/security/2019/01/22/apt-rce.html …
Oops.
*This* is why you use HTTPS. Defense in depth. Take note @videolan.
-
-
Should Apple take note as well? iOS has been doing updates over HTTP for a loooooong time.
1 reply 0 retweets 3 likes -
Well, I mean, Apple wrote their own HTTPS implementation anyway, and then 'goto fail' happened, so maybe Apple users are screwed either way ;-)
2 replies 1 retweet 15 likes -
‘Oops’. Also looks like apt just doesn’t do the smartest thing when fetching assets. iOS also fetches assets at runtime over HTTP, but it then proceeds to check the signature on it, so...
1 reply 0 retweets 0 likes -
The problem here is a fuckup in the way they use their HTTP client. They are trying to handle HTTP redirects at a higher level and have effectively a protocol injection vuln in the Location: URI that lets you bypass signing.
1 reply 0 retweets 7 likes
So they still check signatures, but they have a vuln at a level *higher* than that, in the way they use HTTP itself. This is the kind of attack surface HTTPS gets rid of, of course.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.