Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution
Max <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Oct 10, 2002 at 07:11:01PM -0500, Paul Roberts wrote: > The real solution to this is to start sending emails to the maintainers of > every package you build that does _not_ have a published public key and > signature file, and ask them to start signing their releases. Ask them to Thats what I'm doing since the irssi trojan. I keep a list of projects, emails, date and reply status of everybody I sent an email concerning pgp signatures to. The scary thing is that _not a single project_ that I have asked has started to provide pgp sigs yet! That includes huge and widely used projects like samba and mozilla as well as smaller projects like licq and xchat. Some "developers" dont even know of pgp. I hope our pgp-advocating crackers will show them, the hard way. :) What do you think of a webpage containing 1) a list of projects that have pgp sigs 2) a list of projects that dont have pgp sigs + contact information 3) a mini-howto explaining how to use (and the importance of) gpg/pgp pgp-aware users could use this list to easily get contact information for every project so they can send them email requesting pgp sigs. and project maintainers could put a link to the pgp howto so their pgp-unaware users could learn how to verify the pgp sigs. the first two points should be 'interactive', so everybody can add a project to the database and update its status. opinions? Max -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message