3 ms·
> I like what CoreOS does, they don't even provide SSL download links for their isos, it's all plain text http, so they stress that you need to verify the image
by _prometheus 12y ago
> I like what CoreOS does, they don't even provide SSL download links for their isos, it's all plain text http, so they stress that you need to verify the image signature against their GPG signing key which is distributed via github.
Sounds very much like TRTTD. I'll see about this with `sigpipe` (hashpipe with signatures). The fundamental problem is PKI is weak. using github isn't great either.
We need a chain of trust that's sane (CA system is not sane).
- digi_owl 12y agoWhat is "sane" when you are potentially up against attackers that may have clusters to brute force collision with?