Re: [arch-general] git undetectable tag replacement? (Was: Sébastien Luttringer and Tobias Powalowski)

2017-07-03 Thread Giovanni Santini via arch-general
Il 03/07/2017 04:14, Eli Schwartz via arch-general ha scritto: > > So I was under the impression that git tags encode the tagname in the > actual blob, and I didn't see how that attack (rooted in the basic > nature of a branch as a lightweight, mutable, *pushable* pointer to a > commit) was suppos

Re: [arch-general] Sébastien Luttringer and Tobias Powalowski

2017-07-03 Thread Damjan Georgievski via arch-general
On 3 July 2017 at 01:22, Eli Schwartz via arch-general wrote: > On 07/02/2017 07:01 PM, Ismael Bouya wrote: >> (Mon, Jul 03, 2017 at 12:29:44AM +0200) Morten Linderud : >>> But HTTPS doesnt matter here. We have a trusted signer inn the PKGBUILD, >>> anyone can MITM for the good of their life. >>>

Re: [arch-general] About rebuild of pandoc

2017-07-03 Thread Felix Yan
On 07/03/2017 02:48 PM, Sebastian Reuße via arch-general wrote: > Sebastian Reuße via arch-general writes: > >> Felix Yan writes: > >>> An idea is to provide an alternative package database in the ghc-static >>> package that only contains the boot libraries. You will need to ignore >>> global p

Re: [arch-general] Sébastien Luttringer and Tobias Powalowski

2017-07-03 Thread Ralf Mardorf
On Sun, 2 Jul 2017 22:39:37 +0200, NicoHood wrote: >I've checked the links and while those suggestions are a bit harsh, >they are still valid: > >* btrfs-progs can use stronger hashes. Hi, the subject doesn't mention that "btrfs-progs can use stronger hashes", the subject actually is "Sébastien L