Re: A repository changed its public key?
- From: birre <spamtrap@xxxxxxxxxxxx>
- Date: Thu, 24 Jan 2008 12:25:35 +0100
On 2008-01-23 11:31, houghi wrote:
Andreas wrote:http://lists.opensuse.org/opensuse-announce/2008-01/msg00010.html
I recieved the email as well. I was just too lazy to look up the URL.
:-D
houghi
Trust is the key here, so who do we trust?
Since the beginning of free software and opensource, we have no reason
to not trust the good peoples that help us be happy, but now we also
have evil peoples that will kill free software and will do anything to
infiltrate the distributions if they can.
Since we must trust the distributor of our system, I should prefer that
they also update my system with the keys from the contributors they trust,
so I don't fall in the trap to trust a key from some false contributor.
I have not the skill to validate the keys, other then hope the site is intact
and the key is real.
Or, at least something as rpmkey.KDE_OBS.rpm on the main repository, and not only from the same site, even if it's unlikely someone can mirror it, hack the
code, sign everything with the false key and make us download from there.
I'm not paranoid , but if it's possible even if very hard, some one will for sure try some time.
Many users of linux is trained by the windows software where they learn to click on anything even if they have no chance to know what to answer.
Like the antivirus program say they have virus, and are asked if they will
remove it. (yes or no) , and they call me.
I ask them "what program ask that", and they say, "I don't know"
So, maybe it was the virus itself or the antivirus program, who know.
It must not be like this with keys, someone we trust must trust them first so
we don't get fooled so easy.
/bb
.
- Follow-Ups:
- Re: A repository changed its public key?
- From: Harold Stevens
- Re: A repository changed its public key?
- From: houghi
- Re: A repository changed its public key?
- References:
- A repository changed its public key?
- From: Nikos Chantziaras
- Re: A repository changed its public key?
- From: Michael Soibelman
- Re: A repository changed its public key?
- From: Andreas
- Re: A repository changed its public key?
- From: houghi
- A repository changed its public key?
- Prev by Date: Re: Help 10.3 a mess After YOU Upgrade
- Next by Date: Re: A repository changed its public key?
- Previous by thread: Re: A repository changed its public key?
- Next by thread: Re: A repository changed its public key?
- Index(es):
Relevant Pages
|