summaryrefslogtreecommitdiff
path: root/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
diff options
context:
space:
mode:
authorstefan <stefan@i3mint.local>2026-02-22 15:38:16 +0100
committerstefan <stefan@i3mint.local>2026-02-22 15:39:08 +0100
commit0198667ca2da1a9d070ea17676de75079128f5d9 (patch)
tree32b3ca5c0bf8f0536092b5da466ddf1ccc2b02a4 /PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
parent144a616fdbce6957d9226343cbd2800db983c92b (diff)
300-NetBSD-RelEng-STRIDE
Diffstat (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc')
-rw-r--r--PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc11
1 files changed, 11 insertions, 0 deletions
diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
index f3f7e37..59e3da1 100644
--- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
+++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc
@@ -12,3 +12,14 @@ image::100-GnuPG-Keysigning-DFD.png[]
image::100-GnuPG-Keysigning-SEQ-KSP-WoT.png[]
+
+
+== NetBSD RelEng Attack STRIDE
+
+The ISO Image is built, signed and uploaded to the WWW server, as well as the Signature file and checksums.
+
+Evil Black Hat hacks the webserver, and swaps the ISO image for a manipulated one with a valid Signature.
+
+The manipulated Signature verifies the fake-integrity of the manipulated ISO image, but not the authenticity.
+
+image::300-NetBSD-RelEng-STRIDE.png[]