Debian sources have limited file integrity

Luke <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <[email protected]>
Hello,
Many downstream projects are using your source files directly from your
FTP and packaging. This presents a problem.

1) Navigate to https://ftp.de.debian.org/debian/pool/main/
2) Click on ANY folder/subfolder of a popular project.
3) The only checksum can be found in the .dsc file.

While having the .dsc file is better than nothing, it does not allow
downstream to run GPG verification against the source files themselves.
Additionally, .dsc files only have SHA256 as the strongest checksum.
SHA1 and MD5 have been considered weak/broken for some time, per
Debian's own documentation.

Please consider implementing a system similar to kernel.org's -
https://mirrors.kernel.org/sourceware/lvm2/releases/

In this scenario, each source tarball is signed with GPG, and a
SHA512SUM is included for the entire directory as well. Downstream can
then verify the GPG signature and the checksum easily.

Thank you for your time and concern.


Sincerely,
Luke
Parabola GNU/Linux-libre Packager
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYJ9J6AAoJEMP0/88+roaXeakP/iQe/BBMvj1D/iq+iRRAI1wB
povmCZnUPq8xw/q0N8Fs23le5rxerx4YRbOmWSKNrmlhjgEGY8yehxRAccPmk5Ij
I2AxcLkEH3iNd18H1p+gAiVI7mG6mIBByIctny0DLvVbInHicw8Q6M/7eOvRXF+x
D3AOAmQw3NhU7gs0ikYQeGeVSbn4qiuTSIzc2n3RpWTNrbbyyLb8rPGayUpCrv7Y
IVBkn5Yy27rYumE07H62zN2OtES7zayejevZ+KCblkJCoI+r2fRAoIOirjr/Pc9F
PdALdMW/S7Fy3w9xPS3UrbUpIEW+42ysm095KuAtwMjLmfGT10LE3sueTs7TuHtw
wWBxsCYymHRASx7i+mZiA2ikgUaeP2G9QOnoaIeBNaK/9Id5qOwSUTvJsBtB2wmu
tQxBnZjsl9NarC/rzNJImKuoefDmlgA1tRl/UrBZYGAXhDlL/j5p3b765Y6FRcP+
BJC2uunSv0AD+UsHsjlMEz3dvPcicU7nZ0Klq9jasu+uBChYYXgNEdsWyMFDSjuB
SWJDSOp9Z7ilwLxHM77T/L0famnAayMjb2nLuStgJb2GTASIdJLfHcIUudiW06nl
Ewx4/cWv8VOWpk6l3anOuKH740wVi0mkJ2ehBkbKl/3DGLXbgWJknuwLmGnU06hR
xwz6Q/k3UEcEsi21dDC2
=Z/4D
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.