Re: PGP signing releases - Mailing list pgsql-hackers

From Kurt Roeckx
Subject Re: PGP signing releases
Date
Msg-id 20030203195503.GA12917@ping.be
Whole thread Raw
In response to Re: PGP signing releases  (Greg Copeland <greg@CopelandConsulting.Net>)
Responses Re: PGP signing releases  (Curt Sampson <cjs@cynic.net>)
Re: PGP signing releases  (Greg Copeland <greg@CopelandConsulting.Net>)
List pgsql-hackers
On Mon, Feb 03, 2003 at 12:24:14PM -0600, Greg Copeland wrote:
> On Sun, 2003-02-02 at 20:23, Marc G. Fournier wrote:
> 
> > right, that is why we started to provide md5 checksums ...
> 
> md5 checksums only validate that the intended package (trojaned or
> legit) has been properly received.  They offer nothing from a security
> perspective unless the checksums have been signed with a key which can
> be readily validated from multiple independent sources.

If you can get the md5 sum of "multiple independent sources",
it's about the same thing.  It all depends on how much you trust
those sources.

I'm not saying md5 is as secure as pgp, not at all, but you can't
trust those pgp keys to be the real one either.


Kurt



pgsql-hackers by date:

Previous
From: Lamar Owen
Date:
Subject: Re: v7.3.2 Tag'd and Bundle'd ...
Next
From: "Marc G. Fournier"
Date:
Subject: Re: v7.3.2 Tag'd and Bundle'd ...