Proposal: Trust feeds served via HTTPS without GPG signature

"Bastian Eicher" <[email protected]> Tue, 15 May 2018 19:42:42 +0200
Newsgroups gmane.comp.file-systems.zero-install.devel
Message-ID <[email protected]>
Hello all,

creating Zero Install feeds is pretty straight-forward for new users, thanks
to Thomas' great documentation. Especially the fact that hosting feeds only
requires an HTTP server serving static files makes the entry barrier very
low. However, the step of signing feeds with GPG signatures adds a slight
hurdle. Rather than simply editing XML files with whatever method they
chose, publishers must always include tools like 0publish or 0repo in their
workflow. While these are fairly easy to get up and running it still lacks
the simplicity of "just write a file and upload it".

There seems to be a trend for modern package-manager-like systems to rely on
HTTPS for verifying the identity and integrity of a package. Docker images
pulled from registries are a great example of this. This meshes well with
the wide-spread adoption of Let's Encrypt that make TLS certificates just as
accessible as GPG keypairs.

I would therefore like to propose a new "feature" for Zero Install: Trust
any feed downloaded from an HTTPS URL even if it does not have a GPG
signature.

What do you guys think about this? Would it help with adoption? Would we be
opening up potential security problems?

Regards
Bastian


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot