From: Kevin Smith Date: Tue, 03 May 2005 00:24:04 GMT Subject: Re: Mercurial 0.4b vs git patchbomb benchmark Message-ID: <4276C4A4.6020103@qualitycode.com> In-Reply-To: <200505022106.OAA28850@emf.net> Tom Lord wrote: > More bluntly, given just a (1),(3) pair, Bob is extending his vulnerability > to include a reliance on Alice's patch-computing tools. If Alice were > known to be signing a (1),(2) pair which she had reviewed in detail, > then Bob's vulnerability stays at just his local patch-handling tools > and his general trust of Alice. I'm no expert, but it seems the opposite argument could be made as well. By signing (1)(3), I am asserting that (3) is, in fact, what I intended the end result to be. If I instead sign (1)(2), then it is possible that your patching tools might end up producing something other than (3). Personally, I still like the self-contained nature of signing (1)(2), but I haven't yet heard a security argument in its favor. Kevin