For a security-oriented distribution such as Liberté Linux, peer review of its capability to resist malicious attacks is a highly desirable feature. If you possess the relevant expertise, you are welcome to criticize Liberté's design or implementation by sending me an email. The reason that I ask to send an email is that right now, this site's engine does not have anonymous edits turned on. If your arguments are reasonable, they will appear here on a short notice (with a reply).

Below, some specific pivotal potential vulnerabilities worthy of exploration are listed.

Cables communication

Since the 2011.1 release, Liberté implements secure and anonymous communication using email-like addresses. Potential (i.e., undiscovered) weaknesses of this cables exchange system may include:

  • Circumventing proper message authentication via a communication protocol fault
  • Misrepresenting another user (as cable sender or receiver)
  • Convincing the sender to encrypt a cable for unintended recipient (e.g.: certificates chain verification issue, multiple certificates in a single pem file, …)
  • Exploiting a remote system via a specially formatted certificate / message
  • Known-plaintext attack by generating specially crafted message receipt requests (e.g.: padding doesn't work as expected)
  • Susceptibility to traffic analysis

and similar vulnerabilities.

Code audit

If you have performed an audit of source code in Liberté Linux, please send me the SVN revision or release tag at which you looked, and your review (or a link to one), and I will post / link to it here.


Some useful references are listed below.

