On Wed, Dec 05, 2007 at 11:59:31AM -0500, Nick Guenther wrote:
I don't see what is the problem with blessing a fingerprint of the
binaries with a PKI signature, which would mean that *these* are the
binaries the devs intended to release.
Come on... twice a year and get the benefit of not being excluded from
company policies which require digital signature of software downloaded
through the internet.
> You can check the MD5 files for the main distribution, and for
Definitely not a great answer, as there are vectors of attack which
cover the client acessing the mirror and not the mirror in itself, like
changing on-the-fly the md5sums to match the bad binaries, etc...
A digital signature would enable the non-repudiation of the fingerprints
file (at least), giving a moderate level of assurance that attack
vectors would have to concentrate on upstream development servers (where
the devs *really* know what they are doing).
Rui
--
Hail Eris!
Today is Prickle-Prickle, the 47th day of The Aftermath in the YOLD 3173
+ No matter how much you do, you never do enough -- unknown
+ Whatever you do will be insignificant,
| but it is very important that you do it -- Gandhi
+ So let's do it...?
| Heiko Carstens | [patch -mm] s390: struct bin_attribute changes |
| Andrew Morton | 2.6.25-rc2-mm1 |
| Eric W. Biederman | Re: [PATCH] kexec: force x86_64 arches to boot kdump kernels on boot cpu |
| Jan Engelhardt | intel iommu (Re: -mm merge plans for 2.6.23) |
git: | |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Jens Axboe | Re: [BUG] New Kernel Bugs |
| Andrew Morton | Re: [PATCH] PHYLIB: IRQ event workqueue handling fixes |
