Re: asdf-install and pgp

Daniel Barlow <[email protected]>
Newsgroups gmane.lisp.cclan.general
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Miles Egan <[email protected]> writes:

> FreeBSD and Gentoo solve this problem by checksumming the source
> package.  Could we accomplish this simply by adding an md5sum field to
> the download link on the cliki page?

But anyone who wants to edit the download link and make it point to
their own malicious code somewhere else can also edit the md5 on the
page to correspond to their trojanned package.

(Actually this is still a problem with asdf-install in that they can
sign their own malicious package with their own key and if you have
keys for such bad people on your keyring it'll get installed anyway.
What we _really_ need is some way of saaying "I trust content from
this person", not just "I trust this person is who he says he is".
But at least then you know afterwards who was responsible for
subverting your system ...)


- -dan

- -- 

   http://www.cliki.net/ - Link farm for free CL-on-Unix resources 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+5OkXHDK5ZnWQiRMRAnl+AJ9avrTIW7vYpVz9c21QHfz3fKiUlgCgwtLm
KQwz1g52Q9/bBJAuqlc4zEk=
=3Zib
-----END PGP SIGNATURE-----


-------------------------------------------------------
This SF.net email is sponsored by:  Etnus, makers of TotalView, The best
thread debugger on the planet. Designed with thread debugging features
you've never dreamed of, try TotalView 6 free at www.etnus.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.