1 |
On Mon, 2004-02-16 at 22:20, Brian Klauss wrote: |
2 |
> Why not take package security one step deeper to ensure the validity |
3 |
> of every ebuild and source-tree? |
4 |
> |
5 |
> Instead of relying upon a master hash of the compressed package, |
6 |
> create a hash for each source file, documentation, makefile, etc. |
7 |
|
8 |
Sorry, I don't see what that would give. If the md5 of the compressed |
9 |
archive is fine, then we know already that it has not been tampered |
10 |
with. Ergo, all contained files are fine. |
11 |
|
12 |
(except for the theoretical possibility of md5-sum collision, which is |
13 |
unlikely to an astronomical degree, and not worth worrying about in real |
14 |
world) |
15 |
|
16 |
Heikki |
17 |
|
18 |
-- |
19 |
Heikki Levanto LSD - Levanto Software Development <heikki@×××.dk> |
20 |
|
21 |
|
22 |
-- |
23 |
gentoo-security@g.o mailing list |