git.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Lack of detached signatures
@ 2011-09-27 23:48 Joseph Parmelee
  2011-09-28  0:03 ` Junio C Hamano
  0 siblings, 1 reply; 24+ messages in thread
From: Joseph Parmelee @ 2011-09-27 23:48 UTC (permalink / raw)
  To: git

Hello all:

Under the present circumstances, and particularly considering the
sensitivity of the git code itself, I would suggest that you implement
signed detached digital signatures on all release tarballs.  Just a crypto
hash by itself, however strong, does not protect against man-in-the-middle
attacks.

Joseph

^ permalink raw reply	[flat|nested] 24+ messages in thread

end of thread, other threads:[~2011-09-29 20:31 UTC | newest]

Thread overview: 24+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-09-27 23:48 Lack of detached signatures Joseph Parmelee
2011-09-28  0:03 ` Junio C Hamano
2011-09-28  0:07   ` Michael Witten
2011-09-28  4:17     ` Olsen, Alan R
2011-09-28  7:41       ` Carlos Martín Nieto
2011-09-28 12:36         ` Joseph Parmelee
2011-09-28 16:45           ` Junio C Hamano
2011-09-28 16:55             ` Michael Witten
2011-09-28 16:59             ` Matthieu Moy
2011-09-28 22:25             ` Jeff King
2011-09-28 23:09               ` Ted Ts'o
2011-09-29  0:28                 ` Junio C Hamano
2011-09-29  1:59                   ` Ted Ts'o
2011-09-29  3:50                     ` Junio C Hamano
2011-09-29 13:18                       ` Ted Ts'o
2011-09-29 14:40                         ` Sverre Rabbelier
2011-09-29 14:50                           ` Ted Ts'o
2011-09-29 14:52                             ` Sverre Rabbelier
2011-09-29 16:47                         ` Joseph Parmelee
2011-09-29  1:29                 ` Joseph Parmelee
2011-09-29  1:41                 ` Jeff King
2011-09-29 20:31                 ` Olsen, Alan R
2011-09-28 22:40             ` Joseph Parmelee
2011-09-28 17:03       ` Ben Walton

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).