xeta security model, and hello

Chris Frey <[email protected]> Tue, 28 Oct 2003 16:32:24 -0500
Newsgroups gmane.linux.zynot.general
Message-ID <[email protected]>
Hi there,

Just heard of this project last night, and was pleased to discover that
you're focusing on the embedded space, and that you're open to securing
the portage tree and the tools used to access them.

I was reading the proposed security model at
http://wiki.zynot.org/tiki/tiki-read_article.php?articleId=30
and have some comments.

It sounds like the security model is more based on SSH or SSL-like
transports than GPG signing of the tree itself.  In my opinion, if you
do the GPG signing, a lot of the problems that SSH and SSL solve
are solved already.

It won't matter where the user gets the tree, since it is signed.  As long
as he has the proper key (which SSH/SSL can help with downloading), the
mirrors could be compromised and he'd still be safe.

If I've misunderstood the entire goal and purpose, I apologise.  Just thought
I'd add my $0.02.

- Chris