oss-sec mailing list archives

Re: upstream source code authenticity checking


From: Dag-Erling Smørgrav <des () des no>
Date: Fri, 26 Apr 2013 10:25:04 +0200

Kurt Seifried <kseifried () redhat com> writes:
This makes no sense. So you don't trust their signature because they
have to "earn trust", but you do trust their software and you compile
and run it? That's literally insane.

This is exactly the logic used by web browsers to justify scaring users
away from https sites that haven't payed the Verisign tax...

DES
-- 
Dag-Erling Smørgrav - des () des no


Current thread: