Re: asdf-install and pgp
Daniel Barlow <[email protected]>
| Newsgroups | gmane.lisp.cclan.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Miles Egan <[email protected]> writes: > FreeBSD and Gentoo solve this problem by checksumming the source > package. Could we accomplish this simply by adding an md5sum field to > the download link on the cliki page? But anyone who wants to edit the download link and make it point to their own malicious code somewhere else can also edit the md5 on the page to correspond to their trojanned package. (Actually this is still a problem with asdf-install in that they can sign their own malicious package with their own key and if you have keys for such bad people on your keyring it'll get installed anyway. What we _really_ need is some way of saaying "I trust content from this person", not just "I trust this person is who he says he is". But at least then you know afterwards who was responsible for subverting your system ...) - -dan - -- http://www.cliki.net/ - Link farm for free CL-on-Unix resources -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.1 (GNU/Linux) iD8DBQE+5OkXHDK5ZnWQiRMRAnl+AJ9avrTIW7vYpVz9c21QHfz3fKiUlgCgwtLm KQwz1g52Q9/bBJAuqlc4zEk= =3Zib -----END PGP SIGNATURE----- ------------------------------------------------------- This SF.net email is sponsored by: Etnus, makers of TotalView, The best thread debugger on the planet. Designed with thread debugging features you've never dreamed of, try TotalView 6 free at www.etnus.com.