xeta security model, and hello
Chris Frey <[email protected]> Tue, 28 Oct 2003 16:32:24 -0500
| Newsgroups | gmane.linux.zynot.general |
|---|---|
| Message-ID | <[email protected]> |
Hi there, Just heard of this project last night, and was pleased to discover that you're focusing on the embedded space, and that you're open to securing the portage tree and the tools used to access them. I was reading the proposed security model at http://wiki.zynot.org/tiki/tiki-read_article.php?articleId=30 and have some comments. It sounds like the security model is more based on SSH or SSL-like transports than GPG signing of the tree itself. In my opinion, if you do the GPG signing, a lot of the problems that SSH and SSL solve are solved already. It won't matter where the user gets the tree, since it is signed. As long as he has the proper key (which SSH/SSL can help with downloading), the mirrors could be compromised and he'd still be safe. If I've misunderstood the entire goal and purpose, I apologise. Just thought I'd add my $0.02. - Chris