Re: Re: [Zynot-pkgmgr] Repoteus: Zynot Tree Vision
jesse <[email protected]> 14 Jul 2003 18:39:58 -0700
| Newsgroups | gmane.linux.zynot.zynaut,gmane.linux.zynot.general |
|---|---|
| Message-ID | <[email protected]> |
--===============47768821512430959== Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="=-YlLv405SIYzRCkhEdDpF" --=-YlLv405SIYzRCkhEdDpF Content-Type: text/plain Content-Transfer-Encoding: quoted-printable On Mon, 2003-07-14 at 13:37, Mark Guertin wrote: > On 7/14/03 4:24 PM, "jesse" <[email protected]> wrote: >=20 > > If they are isgned by our devs who are on your keyring .. then you > > should be able to trust. Esp if it's got 2 or more valid sigs. > >=20 > > Over any distrib medium a package that had this requirement would be > > considered pristine. You would be able to check those sigs agains > > keyservers as well as your local copy of the pubkeys.you could trust > > that package if all those check were ok. > >=20 > > If random joe-schmo builds a binary and pops it on p2portage signed. I= t > > doesnt give it any more credability in the eyes of porteous. ( not part > > of or keysystem ). >=20 > That given I would still never allow this on my system, signed or not > signed. Also this would divert a lot of dev attention from working on th= e > distro proper.. Instead they would be building (and yielding TONS of emai= ls > from users if they signed the builds as good and they are not). I know t= his > from experience doing this stuff with Gentoo. >=20 > IMO this is something we should still avoid for now. >=20 > If you haven't noticed I have problems with the whole concept of p2p > distribution of anything for an operating system, and I am not alone on t= his > stuff. =20 >=20 im not pushing for p2p.. Just commenting on the fact that the security model should hold up no matter what method is used for delivery. On binaries or on source :D.=20 I feel exactly the same about p2p as you do.=20 > Potentially this could make M$ email virii look tame from a security > standpoint...if one signed pkg gets compromised and distributed as truste= d > (signed) into a p2p system. With p2p you have zero control after it has > gotten into nodes, that compromised build could live forever, revoking or > no. At least on (semi) controlled mirrors we can properly revoke it if t= he > need should ever arise. >=20 This is a verry real thing in gentoo now, and is no different if the trojan is in source or binary if you have no way to verify its source. We have to assume that at some point this will happen, and have a system that can easuly recover from it.=20 controll if through the keyring and keyservers. Its up to the user. If the files are out in the wild with old invalid sigs It will not be installed ( unless the user wants it that bad ) .. like i stated above Im not pushing p2p but im Definatly pushing a security model that would work in the p2p setting. =20 Remeber that a revocation isn't on a package, but on a key.. So even if there out there with those bad sigs. It's still not "valid"=20 > Mark >=20 --=-YlLv405SIYzRCkhEdDpF Content-Type: application/pgp-signature; name=signature.asc Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQA/E1tu4rKvBkfUvb0RAm/3AJ9XCA3LlMAiWH6Ln19DSW8LEpeVQACaAvkK Om0TsAWyaYBtgQd6Lrl2QRE= =dp7w -----END PGP SIGNATURE----- --=-YlLv405SIYzRCkhEdDpF-- --===============47768821512430959== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zynaut mailing list [email protected] http://lists.zynot.org/mailman/listinfo/zynaut --===============47768821512430959==--