Community discussions

MikroTik App
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Mikrotik resource verify (Solved)

Fri Jan 27, 2017 8:35 pm

Hello.
i just realized the Mikrotik download site "http://www.mikrotik.com/download" is http only, and I can't find anywhere to verify the hash/signature securely, so how can I make sure the resources I downloaded are legit?
Thanks.
Last edited by sam1275 on Fri Feb 03, 2017 3:38 pm, edited 1 time in total.
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Re: Mikrotik resource verify

Wed Feb 01, 2017 5:31 pm

Here's the update.
I emailed to mikrotik support about this issue because it's a pretty important one that affect security, one of the support man kindly enabled https for the download page (I'm not publishing his name in regards of privacy).
However the actual download link is still http only and the md5 hash is not strong enough, combine them together will still allow MIM attack, I emailed back and hope it will get fixed too.
 
User avatar
rextended
Forum Guru
Forum Guru
Posts: 12001
Joined: Tue Feb 25, 2014 12:49 pm
Location: Italy
Contact:

Re: Mikrotik resource verify

Wed Feb 01, 2017 8:11 pm

Here's the update.
I emailed to mikrotik support about this issue because it's a pretty important one that affect security, one of the support man kindly enabled https for the download page (I'm not publishing his name in regards of privacy).
However the actual download link is still http only and the md5 hash is not strong enough, combine them together will still allow MIM attack, I emailed back and hope it will get fixed too.
Do not lost time with this things.

Internal procedure of routeros check if the packages are signed and have valid crc before installing any third party software.
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Re: Mikrotik resource verify

Wed Feb 01, 2017 10:11 pm

Here's the update.
I emailed to mikrotik support about this issue because it's a pretty important one that affect security, one of the support man kindly enabled https for the download page (I'm not publishing his name in regards of privacy).
However the actual download link is still http only and the md5 hash is not strong enough, combine them together will still allow MIM attack, I emailed back and hope it will get fixed too.
Do not lost time with this things.

Internal procedure of routeros check if the packages are signed and have valid crc before installing any third party software.
What about netinstall?
Also Winbox?
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Re: Mikrotik resource verify (Solved)

Fri Feb 03, 2017 3:39 pm

Update: Now the download site is all https supported, thank you mikrotik!
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Re: Mikrotik resource verify (Solved)

Sat Feb 04, 2017 7:24 pm

Those hours would be better spent working on RouterOS and Winbox.
Damn paranoic morons :-E
Of course encryption and security is not for everyone, especially not for a stupid asshole like you.
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Re: Mikrotik resource verify (Solved)

Sat Feb 04, 2017 7:29 pm

I do this in hoping routeros getting better, a hardened security is not only for me, but for every true genius loving Routeros.
If you don't understand, you can keep silent; but if you insult me, I will not respect you any more.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1059
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Mikrotik resource verify (Solved)

Sat Feb 04, 2017 9:44 pm

Well, all kind of security measures will definitely bring MikroTik closer to the requirements that most enterprise customers have nowadays. That includes even small steps like to securing the download areas...
 
sam1275
Member Candidate
Member Candidate
Topic Author
Posts: 110
Joined: Thu May 21, 2015 2:46 pm

Re: Mikrotik resource verify (Solved)

Sun Feb 05, 2017 7:21 am

Security is essential, it have to be considered prior to any other functions. No exceptions, no excuse.
People here seems not care much about that, however that's not my business, I care, so I fight for it.
One don't even need to be here if he have as little brain as Jajeblonsky do.

Who is online

Users browsing this forum: GoogleOther [Bot] and 111 guests