Re: CERT Advisory CA-2002-28 Trojan Horse Sendmail Distribution
Max <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Oct 11, 2002 at 01:22:56PM +0100, Richard Lightman wrote: > > The scary thing is that _not a single project_ that > > I have asked has started to provide pgp sigs yet! > > > I think this needs to be fixed before we start asking people to bother > maintainers. We need to find out why your e-mails are being ignored - > should they contain more information about why to use gpg, how to use > gpg, or perhaps they are too big, and people are skimming them and not > spotting the important bits. My harddisk died a few days ago and I've lost pretty much everything, including the email template and my list of projects. (making backups now, weekly :) The emails were short, like 5 sentences, asking for signatures, providing a link to gpg, explaining the importance and giving examples of previously trojanized projects. Every "developer" should be smart enough to read and understand that in a half minute. AfaIr someone from licq replied telling me he would sign the next release, I still dont find any sigs on their site though. The responsible guy from Mozilla appeared to not understand a thing (http://bugzilla.mozilla.org/show_bug.cgi?id=68079 .. this thread was started by someone else, not me). At least 10 other project maintainers havent replied at all. > Could you post a sample e-mail here? Perhaps a bit of peer review will > result in a template e-mail that maintainers are more likely to listen > to. I will have to create a new one before I can continue my crusade. > > What do you think of a webpage containing > > I think this should wait until you have got some positive feed back > from a few maintainers. I'll wait until Ive got some positive feedback/support from a few users > > 3) a mini-howto explaining how to use (and the importance of) gpg/pgp > > > How about: > http://www.gnupg.org/docs.html I think the gnupg docs are good for people interested in pgp/cryptography, but not for the average joe luser who would click on every virus.exe that you send him if he had ms outlook. I was thinking of a 'scary part' (what a trojan could do), a short intro to the web of trust explaining what signatures are, and finally the exact commands needed to verify their packages' integrity. If someone wants to know more he can still take some time and read the gnupg mini-howto, faq, manual,.. Max -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message