Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-11 Thread Werner Koch
On Fri, 11 Sep 2015 00:05, r...@sixdemonbag.org said: > (Getting an Authenticode certificate, for instance.) FWIW, the Gpg4win installer is code signed. Salam-Shalom, Werner -- Die Gedanken sind frei. Ausnahmen regelt ein Bundesgesetz. ___ Gn

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-11 Thread Werner Koch
Hi, The OP is continuing to "spam" the bug tracker . For the record: OP: [Claims of linking FTP mirrors which are not secure and to the known problem of the non-https gpg4win site.] me: This has nothing to do with gnupg.org. And if you have follo

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-11 Thread Bernhard Reiter
Hi all, On Friday 11 September 2015 at 00:15:51, Daniel Kahn Gillmor wrote: > On Thu 2015-09-10 18:05:35 -0400, Robert J. Hansen wrote: > >> Who else thinks someone should spring for the $10 it would take to > >> buy and install an SSL certificate for the principal distribution > >> point of gpg a

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-11 Thread Werner Koch
On Fri, 11 Sep 2015 00:05, r...@sixdemonbag.org said: > (Getting an Authenticode certificate, for instance.) Yeah, when testing the installer I always see that annoying "unknown issuer" warning. Thus it is probably a good idea to silence this warning by signing the installer. I need to see how

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-10 Thread Scott Lambdin
und bier On Thu, Sep 10, 2015 at 6:05 PM, Robert J. Hansen wrote: > > Who else thinks someone should spring for the $10 it would take to > > buy and install an SSL certificate for the principal distribution > > point of gpg and it's signatures on the worlds most popular > > platform? > > There a

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-10 Thread Daniel Kahn Gillmor
On Thu 2015-09-10 18:05:35 -0400, Robert J. Hansen wrote: >> Who else thinks someone should spring for the $10 it would take to >> buy and install an SSL certificate for the principal distribution >> point of gpg and it's signatures on the worlds most popular >> platform? > > There are many better

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-10 Thread Robert J. Hansen
> Who else thinks someone should spring for the $10 it would take to > buy and install an SSL certificate for the principal distribution > point of gpg and it's signatures on the worlds most popular > platform? There are many better ways for Werner to spend his time and money. (Getting an Authent

Re: plaintext non-ssl distribution - who things this is a good idea?

2015-09-10 Thread Jerry
On Fri, 11 Sep 2015 01:07:52 +1000, cow...@anon.im stated: > Who else thinks someone should spring for the $10 it would take to buy and > install an SSL certificate for the principal distribution point of gpg and > it's signatures on the worlds most popular platform? > > http://gpg4win.org/downlo