Re: [gobolinux-devel] Include version in signed meta data

2008-07-11 Thread Hisham
On Fri, Jul 11, 2008 at 3:56 PM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: > On Fri, 11 Jul 2008 20:27:15 +0200, Hisham <[EMAIL PROTECTED]> wrote: > >> On Fri, Jul 11, 2008 at 1:01 PM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: >>> On Fri, 11 Jul 2008 16:37:51 +0200, Hisham <[EMAIL PROTECTED]> wrote

Re: [gobolinux-devel] Include version in signed meta data

2008-07-11 Thread Jonas Karlsson
On Fri, 11 Jul 2008 20:27:15 +0200, Hisham <[EMAIL PROTECTED]> wrote: > On Fri, Jul 11, 2008 at 1:01 PM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: >> On Fri, 11 Jul 2008 16:37:51 +0200, Hisham <[EMAIL PROTECTED]> wrote: >> >>> On Fri, Jul 11, 2008 at 3:43 AM, Jonas Karlsson <[EMAIL PROTECTED]> wro

Re: [gobolinux-devel] Include version in signed meta data

2008-07-11 Thread Hisham
On Fri, Jul 11, 2008 at 1:01 PM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: > On Fri, 11 Jul 2008 16:37:51 +0200, Hisham <[EMAIL PROTECTED]> wrote: > >> On Fri, Jul 11, 2008 at 3:43 AM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: >>> There has been a proof of concept where a group of people has inject

Re: [gobolinux-devel] Include version in signed meta data

2008-07-11 Thread Jonas Karlsson
On Fri, 11 Jul 2008 16:37:51 +0200, Hisham <[EMAIL PROTECTED]> wrote: > On Fri, Jul 11, 2008 at 3:43 AM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: >> There has been a proof of concept where a group of people has injected >> bad packages into a distribution by asking to be a mirror and providing >>

Re: [gobolinux-devel] Include version in signed meta data

2008-07-11 Thread Hisham
On Fri, Jul 11, 2008 at 3:43 AM, Jonas Karlsson <[EMAIL PROTECTED]> wrote: > There has been a proof of concept where a group of people has injected > bad packages into a distribution by asking to be a mirror and providing > erroneous updates (1). > The issue is not that they provided spoofed, hacke