Re: Verify recent uploads for SourceForge.net project gtkpod
"P.G. Richardson" <[email protected]>
| Newsgroups | gmane.comp.ipod.gtkpod |
|---|---|
| Message-ID | <[email protected]> |
> phantomjinx wrote: >> No problem with those files. > > Of course, they use md5 for checksums, which is really laughable in > response to a security incident. Having detached gpg signatures for > uploads wouldn't be a bad idea, or even just always posting a signed > release announcement that includes a strong checksum (sha256 or > better). > Shouldn't be a problem to auto generate and upload gpg signatures. However, if the account is compromised then those too can be modified. So in reponse to the incident, I did a comparison with my local auto-build versions and they matched, which was more the point. Cheers PGR -- Laws are partly formed for the sake of good men, in order to instruct them how they may live on friendly terms with one another, and partly for the sake of those who refuse to be instructed, whose spirit cannot be subdued, or softened, or hindered from plunging into evil. [The Laws, Plato] You fiend! Never have I encountered such corrupt and foul-minded perversity Have you ever considered a career in the church? Bishop of Bath and Wells (Blackadder II) A clear conscience? When did you acquire such luxuries, Bernard? (Sir Humphrey, Yes Prime Minister) ------------------------------------------------------------------------------ The ultimate all-in-one performance toolkit: Intel(R) Parallel Studio XE: Pinpoint memory and threading errors before they happen. Find and fix more than 250 security defects in the development cycle. Locate bottlenecks in serial and parallel code that limit performance. http://p.sf.net/sfu/intel-dev2devfeb