Gentoo Archives: gentoo-security

From: Peter Simons <simons@××××.to>
To: gentoo-security@l.g.o
Subject: [gentoo-security] Re: Let's blow the whistle
Date: Tue, 09 Nov 2004 11:14:43
Message-Id: 87y8hb5l6e.fsf@peti.cryp.to
In Reply to: Re: [gentoo-security] Re: Let's blow the whistle by Anthony Metcalf
1 Anthony Metcalf writes:
2
3 > I am not seeing the difference between that though and
4 > the signed hashes that are already implemented.
5
6 You are right, technically, there isn't a difference really.
7 The only difference is that a signed list of hashes is very
8 easy to generate, it is very easy to verify, and it needs
9 only one GPG to do it. The solution Gentoo is aiming for in
10 the long run, however, is difficult to create, difficult to
11 verify (without using the Gentoo tools, which you can't use
12 before you have verified them -- bootstrapping!), and it
13 will use several dozen GPG keys. So the only difference is
14 in the complexity.
15
16 My proposal is purely aimed at solving a security problem
17 _right now_, the real solution aims to do much more.
18
19 Peter
20
21
22 --
23 gentoo-security@g.o mailing list