Re: Safety of binary packages
"Wesley W. Terpstra" <[email protected]>
| Newsgroups | gmane.comp.lang.ml.mlton.user |
|---|---|
| Message-ID | <CAA-O0XjFTP_LYrEO+Ud0-JS7A4FdndrLBFKxvB9+0HP784JcjQ@mail.gmail.com> |
On Tue, Aug 6, 2013 at 3:09 AM, Maurício Antunes <[email protected] > wrote: > Sure, I understand. Do you think some kind of basic precautions, like > a https site for download or for a hash for those files, are worthwhile? > If you get your binaries from a linux distribution, these are already signed and verified as correct. You still have to trust the developer, though. But frankly, in any situation where you want to get useful work done, you have to trust the developer any way. I think a similar approach to the MLton website would be more relevant than https, ie: put a gpg signature up for download with the binaries. If the MLton website were compromised, an evil mathematician could just replace the binaries and https would not protect you. Maybe by a group of fundamentalist mathematicians, trying to destroy > the credibility of automated theorem proofs? > That's priceless. ------------------------------------------------------------------------------ Get 100% visibility into Java/.NET code with AppDynamics Lite! It's a free troubleshooting tool designed for production. Get down to code-level detail for bottlenecks, with <2% overhead. Download for free and get started troubleshooting in minutes. http://pubads.g.doubleclick.net/gampad/clk?id=48897031&iu=/4140/ostg.clktrk _______________________________________________ MLton-user mailing list [email protected]; [email protected] https://lists.sourceforge.net/lists/listinfo/mlton-user