On Wed, Dec 05, 2007 at 11:59:31AM -0500, Nick Guenther wrote:I don't see what is the problem with blessing a fingerprint of the binaries with a PKI signature, which would mean that *these* are the binaries the devs intended to release. Come on... twice a year and get the benefit of not being excluded from company policies which require digital signature of software downloaded through the internet. Definitely not a great answer, as there are vectors of attack which cover the client acessing the mirror and not the mirror in itself, like changing on-the-fly the md5sums to match the bad binaries, etc... A digital signature would enable the non-repudiation of the fingerprints file (at least), giving a moderate level of assurance that attack vectors would have to concentrate on upstream development servers (where the devs *really* know what they are doing). Rui -- Hail Eris! Today is Prickle-Prickle, the 47th day of The Aftermath in the YOLD 3173 + No matter how much you do, you never do enough -- unknown + Whatever you do will be insignificant, | but it is very important that you do it -- Gandhi + So let's do it...?
| David Newall | Re: Slow DOWN, please!!! |
| Greg Kroah-Hartman | [PATCH 005/196] Chinese: add translation of SubmittingDrivers |
| Fred . | Please add ZFS support (from GPL sources) |
| Andi Kleen | Please pull ACPI updates |
git: | |
| Peter Stahlir | Git as a filesystem |
| linux | [DRAFT] Branching and merging with git |
| Jakub Narebski | [PATCH 2/n] gitweb: Use '&iquot;' instead of '?' in esc_path |
| Junio C Hamano | Re: irc usage.. |
| Theo de Raadt | That whole "Linux stealing our code" thing |
| Koh Choon Lin | OBSD on MacBook |
| Floor Terra | Re: bcw(4) is gone |
| William Boshuck | Re: Real men don't attack straw men |
| Jim Winstead Jr. | Re: Root Disk/Book Disk Compatibility |
| Desmond A. Kirkpatrick | ATI GUP bug with Linux 'tickler' |
| David C. Niemi | Re: rsh: "rcmd: socket: Permission denied" |
| Theodore Ts'o | Re: help again and again |
