Gentoo Archives: gentoo-dev

From: "Vadim A. Misbakh-Soloviov" <mva@×××.name>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks
Date: Sun, 29 Mar 2015 18:12:42
Message-Id: 2467869.8c83mOlCqD@note
In Reply to: Re: [gentoo-dev] Current Gentoo Git setup / man-in-the-middle attacks by Kristian Fiskerstrand
1 > <pedant>OpenPGP (GPG is just one implementation)</pedant>, but indeed,
2 > that is what the gentoo-keys project is about. There is experimental
3 > support for OpenPGP verification in portage already using gkeys.
4 > Currently the focus is on getting developer's keys up to GLEP63 specs,
5 > i currently see 36 good Gentoo developer keys. The scheme is also
6 > flexible enough to allow for overlays.
7 >
8 >
9 > https is not a good protection against MITM when factoring in global
10 > PKIX CA setup, nor would it protect with regards to server compromise.
11 > So the only viable way to secure ebuild repositories is proper OpenPGP
12 > usage.
13
14 I'd double that pedant paranoid! :)
15
16 --
17 Best regards,
18 mva

Attachments

File name MIME type
signature.asc application/pgp-signature