On Dec 5, 2007, at 7:46 PM, Rui Miguel Silva Seabra wrote:
Who would sign the binaries?
Would each package maintainer sign his own packages?
Does Theo have to sign each package?
I don't see a problem in having signatures for software but I do see
problems in creating and maintaining an infrastructure for these
signatures.
And what would you gain?
What guarantees would these signatures give you?
You can verify package consistency with md5 sums.
If you are paranoid, why would you trust the devs? You would just
compile
the software yourself. But only after reading each line of code of
course.
Floor Terra
| David Miller | Re: [PATCH] Stop pmac_zilog from abusing 8250's device numbers. |
| Andrew Morton | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 010/196] Chinese: add translation of Codingstyle |
| Jan Engelhardt | intel iommu (Re: -mm merge plans for 2.6.23) |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | Re: [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Felix von Leitner | socket api problem: can't bind an ipv6 socket to ::ffff:0.0.0.0 |
git: | |
