Re: Verify recent uploads for SourceForge.net project gtkpod
Todd Zullinger <[email protected]>
| Newsgroups | gmane.comp.ipod.gtkpod |
|---|---|
| Message-ID | <[email protected]> |
phantomjinx wrote: > No problem with those files. Of course, they use md5 for checksums, which is really laughable in response to a security incident. Having detached gpg signatures for uploads wouldn't be a bad idea, or even just always posting a signed release announcement that includes a strong checksum (sha256 or better). -- Todd OpenPGP -> KeyID: 0xBEAF0CE3 | URL: www.pobox.com/~tmz/pgp ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ If the world didn't suck, we'd all fall off. ------------------------------------------------------------------------------ The ultimate all-in-one performance toolkit: Intel(R) Parallel Studio XE: Pinpoint memory and threading errors before they happen. Find and fix more than 250 security defects in the development cycle. Locate bottlenecks in serial and parallel code that limit performance. http://p.sf.net/sfu/intel-dev2devfeb _______________________________________________ Gtkpod-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/gtkpod-devel
signature.asc
(application/pgp-signature, 542 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQFDBAEBCAAtBQJNUI1VJhhodHRwOi8vd3d3LnBvYm94LmNvbS9+dG16L3BncC90 bXouYXNjAAoJEEMlk4u+rwzjWY8IALOjgDZxdk1NrvSpxfgnz2k2/Pun6Mr3lnr6 QOTMJo1i2lVKD7+H6/kPBQU/hYflbhKI/CjxyhjYEDvfznq/v5a/bi9Z5buY872A qOGmXRJ7rrODI2J/b3pz8MgEH8rXwkC/stYSOoMgUSR5zPsZuhkQ+ry1NuQ0+uzt A2MEE4NW1/DKmGFv1ioimSa4n0msRVO9ZhzPJEBM+yM5Hkxw7I1ZWAkD/agqKoZ7 d+31W7I3ayh5xTNkZemlOE738pmeFoftzoeSimEwvNORBYypAMt9Xt7Zjc/Ei5Sh eOgUmHCmR+xshWpOtdr5sVLw+XkvrWUlhQVGLeBMPZoynO70sgk= =tMlc -----END PGP SIGNATURE-----