Re: location of md5 files ... - Mailing list pgsql-www

From Dave Page
Subject Re: location of md5 files ...
Date
Msg-id 937d27e10912141159q16a13c0of96fdf9d8cb9bafb@mail.gmail.com
Whole thread Raw
In response to location of md5 files ...  (Josh Berkus <josh@postgresql.org>)
List pgsql-www
On Mon, Dec 14, 2009 at 7:23 PM, Josh Berkus <josh@postgresql.org> wrote:
> WWW team,
>
> Does Otto have a point?

Yes. From a security perspective, the md5's are useless when
distributed alongside the binaries. That's why I GPG sign my releases
of pgAdmin and the MSI installer - noone else can recreate those
signatures.

There is potentially some benefit to having them there to allow the
user to verify they have a good download though, for example, in the
event of an error untarring.

-- 
Dave Page
EnterpriseDB UK: http://www.enterprisedb.com


pgsql-www by date:

Previous
From: Josh Berkus
Date:
Subject: location of md5 files ...
Next
From: Magnus Hagander
Date:
Subject: Re: location of md5 files ...