Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Time for Open-Source to Grow Up
Jon Lasser, 2002-08-07

The OpenSSH backdoor demonstrates that the community must get pragmatic about package verification, and fast.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
PGP is still the answer 2002-08-10
Sloppy
Whatever you come up with, could just be a degenerate subset of PGP. A web-of-trust system can emulate a hierarchical system; just have the tool come with the distributor's PGP key the same way that, for example, web browsers come with some trusted SSL certs.

No need to invent any new standards,...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus