3 ms·
>I think his point was that many people keep the signature in the same place as the actual binaries Basically, except I meant the key not the signature.
by papsosouid 14y ago
>I think his point was that many people keep the signature in the same place as the actual binaries
Basically, except I meant the key not the signature.
- tptacek 14y agoYou get the key once and its fingerprint is published repeatedly.
- papsosouid 14y agoAnd look at all the linux distros that do that. Oh right, they don't. They just go "here's our public key" and people download it over ftp from the exact spot they are getting the binaries, do nothing to verify it, and pretend that got them security. Hence, theatre. Anyone who would actually do it right already has the tools to do so, ssh public keys work just like pgp public keys.
- tptacek 14y agoYou have no idea what you're talking about. Go troll somewhere else.