Re: Verify recent uploads for SourceForge.net project gtkpod

Todd Zullinger <[email protected]>
Newsgroups gmane.comp.ipod.gtkpod
Message-ID <[email protected]>
P.G. Richardson wrote:
> Shouldn't be a problem to auto generate and upload gpg signatures.
> However, if the account is compromised then those too can be modified.

No one else can create gpg signature using your key (at least, not
without compromising your local system).  So while an attacker could
upload other gpg signatures if SourceForge was compromised, they would
not be made by the proper key and would be easy to determine were not
valid.

That said, I've been called a bit of pedant with security (and other
things).  I will say again that I'm shocked that SourceForge would use
and suggest MD5 for checking integrity after an attack.  MD5 is simply
not strong enough for that purpose anymore.

Without getting too complicated, just routinely including sha256
checksums in the release announcements would help, since those are
mirrored in multiple places where the sums could be checked against a
current download.

-- 
Todd        OpenPGP -> KeyID: 0xBEAF0CE3 | URL: www.pobox.com/~tmz/pgp
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
No one ever went broke underestimating the taste of the American
public.
    -- H. L. Mencken

------------------------------------------------------------------------------
The ultimate all-in-one performance toolkit: Intel(R) Parallel Studio XE:
Pinpoint memory and threading errors before they happen.
Find and fix more than 250 security defects in the development cycle.
Locate bottlenecks in serial and parallel code that limit performance.
http://p.sf.net/sfu/intel-dev2devfeb

_______________________________________________
Gtkpod-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/gtkpod-devel
signature.asc (application/pgp-signature, 542 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iQFDBAEBCAAtBQJNVyLbJhhodHRwOi8vd3d3LnBvYm94LmNvbS9+dG16L3BncC90
bXouYXNjAAoJEEMlk4u+rwzjqhAIAKuJy4WQsAbHxhKZzHlK65f9mjjVlckgYQXs
xE2q1lRL8LnFxpmiotPe7epYbagxrWMzt83CmZm1KJbYsC62aa9rM1FMsE+s/oA3
zT0yGGMdILWCgn4C13KXUGaSL4jl9skN6ZkxztvdjTHHpuMpwDDCvCaVTHRJLQem
I+l6eUHl/j/KXzIYeiZTaizJuz/EauYz6bOwlWWxscON1DI9onPvRUmTeUnlYa4C
11DM/R34O8n9mfeLa4DbtgklgqkBTfVklJTcP9/EmAgL2NOc69L/fypBbQ05P5/I
6GzeVE5rpOLtfnAIdKyQvt3+KAYRw76vxvq+MdKYDnAeDF7gvbY=
=xMdO
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.