4 ms·
So the argument here is that we are trusting github not the author of the software. And that way we can trust the code audit we do on GitHub to be the same as t
by nmcfarl 12y ago
So the argument here is that we are trusting github not the author of the software. And that way we can trust the code audit we do on GitHub to be the same as the downloaded software. So we don't have to use our own software tools to do that audit, we can look at the code on github.
I can see that being a valid argument for github however for self-hosted non-famous authors the fact that they are who they say they are means nothing to me°. And as such I'm going to have to audit the software on my box regardless. (Or just forget about auditing and trust of the world is a safe place - which is what most people do anyhow - and if you are doing that you don't believe in mitm's anyhow.)
°also I would argue that they signed certificate doesn't prove that anyhow. And state actors can forge these anyhow, so we are now talking about people who control your pipes, but not the government, and who hasn't hacked the end point. And
- colechristensen 12y agoThe point is, if you don't verify ssl certificates, you might as well use http. Https with self signed certs provides you no security in any circumstances downloading public software. Self-signed certificates and http connections are trivially intercepted and forged (ever used wifi in a public place?) Signed certificates provide limited proof of identity true, but they can't be forged by jokers hijacking the wifi in a coffee shop.
- deleted 12y ago[deleted]