Provide signed downloads or downloads over HTTPS #98

Closed
opened 2016-09-17 19:41:59 +00:00 by ddevault · 5 comments
ddevault commented 2016-09-17 19:41:59 +00:00 (Migrated from github.com)

Or both!

Or both!

Would BSD signify(1) signatures be acceptable?

Would BSD signify(1) signatures be acceptable?
ddevault commented 2016-09-18 22:30:08 +00:00 (Migrated from github.com)

PGP signatures would be preferable. What's the advantage of signify?

PGP signatures would be preferable. What's the advantage of signify?

The cryptographic primitives provided by OpenPGP are outdated, signify on the other hand uses Ed25519. On top of that, generally, maintaining a PGP key is a pain in the ass (pointless web of trust, key expiry, ASN.1 object identifiers, blah blah blah). Signify on the other hand is similar to maintaining a bitcoin wallet.

The cryptographic primitives provided by OpenPGP are outdated, signify on the other hand uses Ed25519. On top of that, generally, maintaining a PGP key is a pain in the ass (pointless web of trust, key expiry, ASN.1 object identifiers, blah blah blah). Signify on the other hand is similar to maintaining a bitcoin wallet.
ddevault commented 2016-09-18 22:35:37 +00:00 (Migrated from github.com)

I'm not convinced that the primitives have practically exploitable flaws at the moment, and signify deployment is pretty lacking. Could you consider publishing both with a long term plan for switching entirely to signify?

I'm not convinced that the primitives have practically exploitable flaws at the moment, and signify deployment is pretty lacking. Could you consider publishing both with a long term plan for switching entirely to signify?
ddevault commented 2016-09-19 03:13:36 +00:00 (Migrated from github.com)

Thanks!

Thanks!
Sign in to join this conversation.
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: ariadne/pkgconf#98
There is no content yet.