1 |
On Thu, Nov 11, 2004 at 06:38:09PM +0000, Kurt Lieber wrote: |
2 |
> On Thu, Nov 11, 2004 at 01:31:24PM -0500 or thereabouts, Chris Frey wrote: |
3 |
> > Why? The patch Peter posted looked pretty straightforward. It's even simpler |
4 |
> > than I thought it would have to be. I don't understand why it won't work. |
5 |
> |
6 |
> Peter has indicated that signed snapshots will not be sufficient to |
7 |
> mitigate this risk in his eyes. He is still demanding that another |
8 |
> solution be implemented. |
9 |
|
10 |
I don't presume to speak for Peter, but I would assume that the solution he |
11 |
posted to the list is the one he would like implemented. :-) It certainly |
12 |
addresses the main concerns of this thread, as I see it. |
13 |
|
14 |
In another post, you asked whether we expect the devs to drop everything to |
15 |
implement the checking in emerge sync. I certainly don't expect that. Once |
16 |
the signatures are available from the server, any user can use them and |
17 |
write their own code to do the checks. The signature is all we need. |
18 |
|
19 |
- Chris |
20 |
|
21 |
|
22 |
-- |
23 |
gentoo-security@g.o mailing list |