Re: Safety of binary packages

"Wesley W. Terpstra" <[email protected]>
Newsgroups gmane.comp.lang.ml.mlton.user
Message-ID <CAA-O0XjFTP_LYrEO+Ud0-JS7A4FdndrLBFKxvB9+0HP784JcjQ@mail.gmail.com>
On Tue, Aug 6, 2013 at 3:09 AM, Maurício Antunes <[email protected]
> wrote:

> Sure, I understand. Do you think some kind of basic precautions, like
> a https site for download or for a hash for those files, are worthwhile?
>

If you get your binaries from a linux distribution, these are already
signed and verified as correct. You still have to trust the developer,
though. But frankly, in any situation where you want to get useful work
done, you have to trust the developer any way.

I think a similar approach to the MLton website would be more relevant than
https, ie: put a gpg signature up for download with the binaries. If the
MLton website were compromised, an evil mathematician could just replace
the binaries and https would not protect you.

Maybe by a group of fundamentalist mathematicians, trying to destroy
> the credibility of automated theorem proofs?
>

That's priceless.

------------------------------------------------------------------------------
Get 100% visibility into Java/.NET code with AppDynamics Lite!
It's a free troubleshooting tool designed for production.
Get down to code-level detail for bottlenecks, with <2% overhead. 
Download for free and get started troubleshooting in minutes. 
http://pubads.g.doubleclick.net/gampad/clk?id=48897031&iu=/4140/ostg.clktrk

_______________________________________________
MLton-user mailing list
[email protected]; [email protected]
https://lists.sourceforge.net/lists/listinfo/mlton-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.