Re: PyPI/pip security: waiting for input

Daniel Holth <[email protected]> Mon, 11 Mar 2013 10:52:46 -0400
Newsgroups gmane.comp.python.catalog
Message-ID <CAG8k2+4FNdCs4mrOPoBnfLeZCdbW-WOk5zs1AKgPQjcV2kr0FA@mail.gmail.com>
Super impressed after reading all the TUF papers and comparing it to
my own feeble proposal, they had addressed a whole bevy of problems
that I hadn't even thought of - infinite-length download attacks,
server-asserted timestamps, quorum signatures, sophisticated trust
delegation, consistency of all the metadata all the time ...