Re: Gentoo Linux insecurities...

From: Tom St Denis (tomstdenis_at_iahu.ca)
Date: 09/29/04


Date: Tue, 28 Sep 2004 22:38:26 -0400

Ryan Barnard wrote:
> Tom, I posted your question in the Gentoo forums....located here:
> http://forums.gentoo.org/viewtopic.php?t=229875
>
> It looks like there is nothing to worry about...how easy would it be
> to get two different tarballs of the same size that hash to the same
> MD5?
>
> I agree that this is a concern, but it sounds like it's not an
> immediate problem, and the Gentoo developers have a different system
> in the works.

Dan has proven the attack works. He's giving a talk on the idea
sometime in the near future.

Generally the attack would be obvious by looking at the "header" shell
script that decodes the payload.

My point is that it's relatively possible [for instance, Unreal2k3 has
that sort of installer...].

Tom



Relevant Pages

  • Re: I misread the question
    ... You don't have to worry too much about Tom's attack. ... > Tom St Denis wrote: ... > So what analysis materials you would need? ...
    (sci.crypt)
  • dont even try to talk a coconut
    ... We attack them, then we subtly smell Junior and Joey's ... It can quietly excuse behind Tom when the closed ...
    (uk.sport.football.clubs.liverpool)
  • Re: BlackMonk is a coward
    ... I've known him outside of RMB for around 6 years and he's a good guy. ... Tom and I have had MANY heated arguments about myriad things over the years. ... The people who attack her are ... Too much to ignore, folks. ...
    (rec.music.beatles)
  • Re: BlackMonk is a coward
    ... Tom and I have had MANY heated arguments about myriad things over the years. ... obviously as unhinged as fatt when it comes to Yoko. ... The people who attack her are ... Too much to ignore, folks. ...
    (rec.music.beatles)
  • Re: Variable S-boxes
    ... "Tom St Denis" wrote in message ... I showed there was little computational cost of one valid morphing S-box. ... S-box denies that data how does an attack proceed? ... When finished and properly described my cipher (1-2 ...
    (sci.crypt)