1 |
Anthony Metcalf writes: |
2 |
|
3 |
> I am not seeing the difference between that though and |
4 |
> the signed hashes that are already implemented. |
5 |
|
6 |
You are right, technically, there isn't a difference really. |
7 |
The only difference is that a signed list of hashes is very |
8 |
easy to generate, it is very easy to verify, and it needs |
9 |
only one GPG to do it. The solution Gentoo is aiming for in |
10 |
the long run, however, is difficult to create, difficult to |
11 |
verify (without using the Gentoo tools, which you can't use |
12 |
before you have verified them -- bootstrapping!), and it |
13 |
will use several dozen GPG keys. So the only difference is |
14 |
in the complexity. |
15 |
|
16 |
My proposal is purely aimed at solving a security problem |
17 |
_right now_, the real solution aims to do much more. |
18 |
|
19 |
Peter |
20 |
|
21 |
|
22 |
-- |
23 |
gentoo-security@g.o mailing list |