[prev in list] [next in list] [prev in thread] [next in thread] 

List:       secure-desktops
Subject:    Re: [Secure Desktops] Introducing a public db for software and firmware hashes
From:       Joanna Rutkowska <joanna () invisiblethingslab ! com>
Date:       2017-04-14 8:07:27
Message-ID: 20170414080727.GC30521 () work-mutt
[Download RAW message or body]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, Apr 12, 2017 at 11:59:30AM +0200, intrigeri wrote:
> Hi,
> 
> Joanna Rutkowska:
> > Also, in case it wasn't clear: the primary audience for such a DB should be
> > developers or admins (e.g. IT department in a large organization), I think. Not
> > users. Users are always somehow fated to trust the "last mile" vendor, and there
> > is little feasibility in implementing any form of trust distribution for them.
> 
> Thanks, this clearly addresses the main question that popped up in my
> mind when I first read about this initiative.
> 
> Just to make sure I got the idea right, does the following "user"
> story convey a good example of the intended use case?
> 
>   As a person who maintains Tails installations for a number of people
>   (e.g. to access files sent to SecureDrop), I want to have additional
>   means of verifying the Tails ISO I've downloaded, on top of the
>   various verification means (hash downloaded over pinned HTTPS by our
>   Firefox add-on, OpenPGP detached signature) already made available
>   by the Tails project.
> 
>   Given I create a fork of the canonical codehash.db repo
>   And I regularly merge into my fork the branches from witnesses I trust
>   When I download a new Tails ISO
>   And I run some command line
>   Then I am told which witness certifies I got the same ISO as they did
>   And I am told which witness certifies I got a different ISO than theirs
> 
> Also, did specific admins (IT departments etc.) already express
> interest in maintaining + using this? In particular, I'd love to hear
> what the SecureDrop folks think about it :)  And if not, is there
> a plan to reach out to these people so this data is actually used
> and useful?
> 
> Rationale: before we consider adding one more step to the (already too
> long) Tails release process, I want to make sure I get the intended
> benefit right :)
> 

Hi intrigeri,

Yes, the scenario you described above is exactly what I have had in mind. So
it's all about answering a question: "Am I in the same boast as <some other
person you consider worthwhile to compare with". 

joanna.

-----BEGIN PGP SIGNATURE-----

iQIcBAEBCAAGBQJY8IM+AAoJEDOT2L8N3GcYoL0P/ip/fcpiFnJbz8oclvHJILQ0
Mlts0wwYS3VGNhoA2r3/yQ1nG8xDMv5LutdnhhIIVu8boABnzQ2+E3o1mwa8HAXJ
sLmYO4dzRQt/b3kHHuAiDnf38XWSQyEPdeFBIYCD8PD0d+uuYEWgYo3sCuppz48O
uz29Wklzi6JhtMLANx2WtSjjgckL1pK4A0o9rHc+ZLpYFtmEa0KQhAg759wUqWZZ
hGkVbXo1orbeXpmt06zpcZhdHkKeF4VCYg1VYrp8RYb+wwoE00Is6i7bYfDRC2HY
Eq9U/y1Shd/1ik+IMl4iWA9VrBdDXJrLuyFXY3F8bFzqXdcZUdIj3UvNMOyn6pWc
UIm7MIWQHACT1Eeer2SgSzjKLwLUoLD9vtIlLyMA/Mdm5DsjvO/jytX3yhUSGAK+
heJ31SoIprZs8GdpDGHRxCvvLT3TxJHKXrcSfp2ObRFVpK5ML5YwVSQgjMMX+Jr1
m9KgcdZY/w82Hwm53VjcIw71zd0Wz1H+PNg3k6CN1NPb4IkdsTYccQrhdPy1lDoH
WVsutGiv1GOfLnbXAsXJ57Fqd4jbMtvcbeYrI2CSEWXiNidDO2+hUSlcPqbUoEtx
Xuppd5IDwmJOtQSXbxdU7w2xIKj5c7olhIlftle+e3xp2TSdJymjioy2Seua9GeU
/x21nDL55WMVfrwpKm1C
=EOOw
-----END PGP SIGNATURE-----

_______________________________________________
Desktops mailing list
Desktops@secure-os.org
https://secure-os.org/cgi-bin/mailman/listinfo/desktops

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic