skip to content

An internal crates mirror ingests any crate carrying a valid publisher signature. What can still be served for a requested name?

level: seniorimportance: should knowfreq 44%

answer

  1. membership test, not a decision
  2. no forgery required
  3. substitution and downgrade both pass
  4. signatures have no sense of currency
  5. pin says which, signature says who

basics

~10 s

Any other genuinely signed crate. A signature answers who vouched for some bytes, never whether those bytes are the package and version that was requested, so substitution and downgrade both pass a presence check.

solid answer

~50 s

"A valid signature exists" is a membership test over the publisher's entire signed corpus, not a decision about this request. A compromised operator of a trading firm's internal mirror can serve any genuinely signed crate for any requested name: a different package, or an older version of the right one with a known flaw. Every signature verifies, because the attacker never needs to forge anything — they only choose which authentic artifact to hand over. Signature validity also has no notion of currency, so downgrade is free. What closes it is pinning the expected coordinates and requiring the signed subject to match them: the consumer names the package, version and digest it wants, and the signature then attests the artifact you already chose rather than choosing it for you. Pinning says which bytes; the signature says who stands behind them. Neither substitutes for the other.

go deeper

for a junior

Understand that checking a signature verifies and checking that it is the right artifact are two different steps. Be able to say why 'it is signed' does not answer 'is this the package I asked for'.

for a middle

Explain substitution and downgrade as two ways a genuinely signed artifact can be the wrong one, and why no forgery is required. Describe what the consumer has to record before it asks in order to compare anything.

for a senior

Diagnose the rule in a real ingestion path: what does the check compare against, who chooses the bytes if nothing does, and how would you introduce coordinate pinning without stopping every build. Cover freshness separately.

for a principal

Own the argument that pinning and signing are orthogonal controls, and be ready to defend keeping both when a team proposes dropping one as duplicated effort. Decide who owns the intended-coordinates record across the estate.

## Membership versus identity A rule of the form *accept an artifact if some valid signature from a trusted publisher exists over it* is a membership test. It asks: is this artifact somewhere in the set of things our trusted publishers have ever signed? For a large ecosystem that set is enormous — every package, every version, every historical release. The question you actually needed answered is much narrower: **is this the artifact I requested?** A membership test cannot answer it, because the requested coordinates never enter the check. That gap is not theoretical. Consider a proprietary trading firm running an internal crates mirror for its build fleet, gating ingestion on "a valid signature exists". An operator of that mirror — an insider, or an attacker who has taken over the mirror service — decides which bytes are returned for a requested name. They do not need a key, a forged signature, or a compromised publisher. They pick a different, genuinely signed crate and serve it under the requested name. Every downstream verification passes. The assets at stake are the firm's money and its strategy code, and the control that was supposed to protect them approved the substitution. ## Two shapes of the same hole **Substitution.** A differently named crate, or a crate from a different publisher inside the trusted set, is returned for the requested name. If the consumer only checks "signed by someone we trust", the name never gets compared to anything. **Downgrade.** The right crate, at an older version the publisher genuinely signed, carrying a flaw fixed since. This one is nastier because nothing about it looks wrong: correct name, correct publisher, authentic signature. Signature validity has no notion of currency — an old release stays validly signed forever. Freshness is a property the *metadata* layer has to carry (expiry, version floors, a signed index of what the current release is); it is not something a signature check will ever notice on its own. ## Why the rule is tempting It is cheap. It needs no per-package configuration, no expected-identity list to maintain, no coordinates to keep in sync, and it produces a green check in a pipeline. It also *feels* rigorous because cryptography is involved. But it collapses a two-part decision — *which artifact* and *whose artifact* — into one boolean about the second part, and then silently answers the first with whatever the mirror handed over. ## What actually closes it The consumer must name what it wants before it asks, and then require the signed claim to be about that: - **Pin the coordinates.** Record the exact package name, version and content digest you intend to consume, in a lockfile or equivalent, and resolve against that record rather than against whatever the mirror offers. - **Match the signed subject to the request.** Verification succeeds only when the digest of the artifact you resolved appears in the signed statement's subject *and* those coordinates are the ones you asked for. The signature then attests the artifact you already chose. - **Keep the freshness decision separate.** Something other than the signature must say which version is current, or downgrade stays open. ## Signature and pinning are orthogonal This is the sentence to be able to say cleanly: | Question | Answered by | | --- | --- | | Which bytes am I actually consuming? | the digest I pinned | | Who stands behind those bytes? | a signature over that digest | | Are these the bytes I asked for? | matching the signed subject against the coordinates I requested | | Are these bytes safe to run? | neither of them | A pin without a signature fixes the content but tells you nothing about its origin — and the first resolution that produced the pin was itself an unauthenticated choice, so a bad artifact pinned early stays pinned. A signature without a pin tells you an identity vouched for *something* and lets someone else pick which something. Teams reach for "we sign everything, so we do not need to pin" because both controls sound like integrity controls, and they are not: one fixes *which*, the other establishes *who*. Dropping either leaves a hole the other never covered. ## The interview answer in one breath A valid signature is necessary and nowhere near sufficient. Ask what the check compares the signature *against* — if the answer is "nothing, it just has to verify", then the artifact selection is being made by whoever serves the bytes, and the cryptography is decorating their choice.

  • The mirror pins exact versions and digests from a lockfile. Does it still need signatures?
    Yes. Pinning freezes which bytes you consume but says nothing about who produced them, and the resolution that first created each lockfile entry was itself an unauthenticated choice — a bad artifact pinned on day one stays pinned faithfully forever. The signature is what makes the origin of the pinned bytes accountable and lets you re-evaluate every artifact you accepted from an identity you later stop trusting.
  • How would you detect that a downgrade rather than a substitution has occurred?
    Not from the signature — an old release stays validly signed indefinitely. You need something that asserts what the current version is: a signed, expiring index of releases, a version floor enforced at resolution, or a comparison of the resolved version against the pin. Detection after the fact means comparing the digests actually consumed against the digests you intended, which is only possible if you recorded the intent.
  • Why is 'a valid signature exists' such a common rule in real pipelines?
    Because it is cheap and it looks rigorous. It needs no expected-identity list, no coordinates kept in sync, and no per-package configuration, and it emits a green check involving cryptography. The cost is hidden: it collapses two decisions — which artifact and whose artifact — into a boolean about the second, and lets whoever serves the bytes answer the first.

A bouncer confirming a wristband is genuine has still not confirmed that this person is the guest you invited. Both checks are needed, and only one of them was performed.

saying these in an interview costs you the question

  • Treats presence of a valid signature as artifact selection
  • Says pinning is redundant once everything is signed
  • Ignores downgrade to an older, genuinely signed version
  • Assumes an attacker must forge something to substitute
  • Believes signature validity conveys freshness or currency

context