tb-updater should authenticate file names

Information

ID: 98
PHID: PHID-TASK-zgfpxpxchdbs3xzqnfvc
Author: Patrick
Status at Migration Time: resolved
Priority at Migration Time: Normal

Description

To do this, the sha256sums.txt file needs to be verified using the sha256sums.txt.asc file. When that succeeded, the hash for the archive needs to be created and looked up within sha256sums.txt.

This is useful to detect a downgrade or indefinite freeze attack.

Comments


Patrick

2015-01-17 05:20:03 UTC