Re: Mercurial 0.4b vs git patchbomb benchmark
- From
- Kevin Smith <yarcs@qualitycode.com>
- Date
- May 3, 2005, 00:24 UTC
- Message-ID
- <4276C4A4.6020103@qualitycode.com>
- In-Reply-To
- <200505022106.OAA28850@emf.net>
Tom Lord wrote:
Show 5 quoted lines
> More bluntly, given just a (1),(3) pair, Bob is extending his vulnerability > to include a reliance on Alice's patch-computing tools. If Alice were > known to be signing a (1),(2) pair which she had reviewed in detail, > then Bob's vulnerability stays at just his local patch-handling tools > and his general trust of Alice.
I'm no expert, but it seems the opposite argument could be made as well. By signing (1)(3), I am asserting that (3) is, in fact, what I intended the end result to be. If I instead sign (1)(2), then it is possible that your patching tools might end up producing something other than (3).
Personally, I still like the self-contained nature of signing (1)(2), but I haven't yet heard a security argument in its favor.
Kevin