Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution

Max <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Thu, Oct 10, 2002 at 07:11:01PM -0500, Paul Roberts wrote:

> The real solution to this is to start sending emails to the maintainers of
> every package you build that does _not_ have a published public key and
> signature file, and ask them to start signing their releases.  Ask them to

Thats what I'm doing since the irssi trojan. I keep a list of projects,
emails, date and reply status of everybody I sent an email concerning
pgp signatures to. The scary thing is that _not a single project_ that
I have asked has started to provide pgp sigs yet! That includes huge and
widely used projects like samba and mozilla as well as smaller projects
like licq and xchat. Some "developers" dont even know of pgp. I hope
our pgp-advocating crackers will show them, the hard way. :)

What do you think of a webpage containing
1) a list of projects that have pgp sigs
2) a list of projects that dont have pgp sigs + contact information
3) a mini-howto explaining how to use (and the importance of) gpg/pgp

pgp-aware users could use this list to easily get contact information
for every project so they can send them email requesting pgp sigs. and
project maintainers could put a link to the pgp howto so their pgp-unaware
users could learn how to verify the pgp sigs.

the first two points should be 'interactive', so everybody can add a
project to the database and update its status.

opinions?

Max

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.