Gentoo Archives: gentoo-security

From: Marius Mauch <genone@g.o>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Re: Out of air
Date: Wed, 10 Nov 2004 07:22:57
Message-Id: 20041110082234.1c8bc79d@sven.genone.homeip.net
In Reply to: Re: [gentoo-security] Re: Out of air by Chris Haumesser
1 On Tue, 09 Nov 2004 23:04:39 -0800
2 Chris Haumesser <ch@××××.ws> wrote:
3
4 > > Then there is also the up to six
5 > >month transition period between this solution and the solution that
6 > >is currently being implemented.
7 > >
8 > If portage support for this temporary hack is not implemented, there
9 > is clearly no six month transition period. Just that one day, those of
10 > us who have been manually verifying the signature will no longer need
11 > to do so.
12
13 Well, verifying the signature only shows you that noone has modified the
14 file containing the hashes, you still have to verify that the hashes
15 match the actual files and I really doubt that you want to do that
16 manually for ~100000 files.
17
18 Marius
19
20 --
21 Public Key at http://www.genone.de/info/gpg-key.pub
22
23 In the beginning, there was nothing. And God said, 'Let there be
24 Light.' And there was still nothing, but you could see a bit better.