Re: Debian sources have limited file integrity

Luke <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <[email protected]>
On 11/12/2016 09:39 PM, Luke wrote:
> Hello,
> Many downstream projects are using your source files directly from your
> FTP and packaging. This presents a problem.
>
> 1) Navigate to https://ftp.de.debian.org/debian/pool/main/
> 2) Click on ANY folder/subfolder of a popular project.
> 3) The only checksum can be found in the .dsc file.
>
> While having the .dsc file is better than nothing, it does not allow
> downstream to run GPG verification against the source files themselves.
> Additionally, .dsc files only have SHA256 as the strongest checksum.
> SHA1 and MD5 have been considered weak/broken for some time, per
> Debian's own documentation.
>
> Please consider implementing a system similar to kernel.org's -
> https://mirrors.kernel.org/sourceware/lvm2/releases/
>
> In this scenario, each source tarball is signed with GPG, and a
> SHA512SUM is included for the entire directory as well. Downstream can
> then verify the GPG signature and the checksum easily.
>
> Thank you for your time and concern.
>
>
> Sincerely,
> Luke
> Parabola GNU/Linux-libre Packager
>
>
Hello,
I forgot to mention - HTTPS is also not properly functioning on
ftp.debian.org. Please consider adding HTTPS support as soon as possible.


Thank you.

Sincerely,
Luke
Paraboal GNU/Linux-libre Packager
signature.asc (application/pgp-signature, 801 B)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJYKJr2AAoJEMP0/88+roaXOpIP/19gPNA5O56CtDXOGQ+hoaPM
B+13JkssFJcF+Pd9T2v/8j2uCQrLf/e9+SG/kR6/RyZCHnvDIHaP7jOeNPx8wN9G
Agt9nK9Q2g9ulHgyKxKniu4p2MHyfEwerQ+kieGL63FmjYemFAI3JCb3J0OZuZIZ
JQ8oZB2HoXfd0Sguz36F8Fs5QogGQpjWmDY8brPr+kJmDX4flygByWNyZWMT/m7v
FGefMvCJQy5A8aJGAz1e/EA9Ir4L1nuVhsVIzJNuZgl8nP021lfRYOxkTS/40J/A
MOj64UjeBZlbKwPlFoskohr0tNuN5MMA/mFGL5ggv5YuJQgZYvWE7N3eB9w/Mjbr
cItu81wJk0C3r2m0qQYscWlHo/mM+lhNb32mLjeNZx8WgFGhN7Xt2VSRRpfw4MFZ
gcAv/SwDsfAuCsVLhBLpTLfIJ8XC8a7kbfRzmn/tip1PAN9ZybEhgnbg4HrEppjc
ubsxwzCyonq9e0eG5I7+3jOuiMLdjIL8uNUdCFQ150qzZen/YpayARW+z8vJsJxo
SpKY/fRulGfUVAOWkmNMggB3C4n3bQO3D8LAW9Oj8LdYb1rOZ6KKRxLekGpJjWRf
qTuO5dkJu7iKPFwyRTvO9NWwCu8LXO+05e1/6fIINGQOpTzVyoT3WQZCO+teb9Gf
DLnSaHkXIlo5vWsOAUGF
=S6tV
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.