1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
Andreas Waschbuesch wrote: |
5 |
> I could open some - as ist seems - "usefull" sourceforge-project and |
6 |
> inject any "additional" code on gentoo systems, while submitting a |
7 |
> perfectly "legal" ebuild, signed to "heavenly" trust. |
8 |
|
9 |
The point is that if we implement signing, a user can say, ``Well, I |
10 |
distrust the authors of this sourceforge project'' if they wish. But if |
11 |
we do not, they may trust the authors and yet still not be able to trust |
12 |
the source. |
13 |
|
14 |
So the reasonable, expected behavior from portage is that the source |
15 |
downloaded is the source it claims to be. If we do not trust the |
16 |
original source, we needn't install the package, but if we do, we should |
17 |
be able to trust the package implicity. Right now, we cannot trust the |
18 |
package, even if we trust the original authors. Signing fixes this problem. |
19 |
|
20 |
Again, this is like saying that since we have not had the NSA conduct |
21 |
background checks on each and every open source developer, we should not |
22 |
trust their products. Well, fine, then don't install them. But if you |
23 |
decide you trust the folks at kernel.org, or KDE, or GAIM, or whatever, |
24 |
you should be able to trust the vanilla-sources ebuild, or the kde |
25 |
ebuild, or the gaim ebuild. Right now, you cannot. So even when one does |
26 |
choose to trust upstream, he cannot trust portage. That is broken. |
27 |
|
28 |
- -- |
29 |
Dan "KrispyKringle" Margolis |
30 |
Security Coordinator/Audit Project, Gentoo Linux |
31 |
-----BEGIN PGP SIGNATURE----- |
32 |
Version: GnuPG v1.2.4 (Darwin) |
33 |
|
34 |
iQEVAwUBQY5g5LDO2aFJ9pv2AQKDSAf+KXpMW/CTzVAp3KZjVoPHuHlWutd8U+l1 |
35 |
2NbsMvHEp0dJ4LBPakw48m4Py5jBm8ZkCxLFbo4kd1T1RczDXanuT9ou1K6+qQSk |
36 |
MhEOG+LD/71h+S5NRZUkoaDBhCTPtnXRVlP3SRNSZS2/AxlBWB5wv8U7W/V5i/Fk |
37 |
0klyGfpCSlx9OjR5X1itX4opYd30HP57TTIKuqV0OEgonkHmPR91bJhYo468W5Yc |
38 |
ujz942WmMxuGawjDH163QmABegLbV++tgBJqiyXYguobxOEVRWCoaaJh4PfGvdVd |
39 |
Ce3QyrpVKYavlc8eHUkyLWF8yaBSD4BsBLUGLAvWfnfOc2zDAwbPQg== |
40 |
=5OuB |
41 |
-----END PGP SIGNATURE----- |
42 |
|
43 |
-- |
44 |
gentoo-security@g.o mailing list |