Proposal: Trust feeds served via HTTPS without GPG signature
"Bastian Eicher" <[email protected]> Tue, 15 May 2018 19:42:42 +0200
| Newsgroups | gmane.comp.file-systems.zero-install.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello all, creating Zero Install feeds is pretty straight-forward for new users, thanks to Thomas' great documentation. Especially the fact that hosting feeds only requires an HTTP server serving static files makes the entry barrier very low. However, the step of signing feeds with GPG signatures adds a slight hurdle. Rather than simply editing XML files with whatever method they chose, publishers must always include tools like 0publish or 0repo in their workflow. While these are fairly easy to get up and running it still lacks the simplicity of "just write a file and upload it". There seems to be a trend for modern package-manager-like systems to rely on HTTPS for verifying the identity and integrity of a package. Docker images pulled from registries are a great example of this. This meshes well with the wide-spread adoption of Let's Encrypt that make TLS certificates just as accessible as GPG keypairs. I would therefore like to propose a new "feature" for Zero Install: Trust any feed downloaded from an HTTPS URL even if it does not have a GPG signature. What do you guys think about this? Would it help with adoption? Would we be opening up potential security problems? Regards Bastian ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot