Lack of detached signatures
- From
- Joseph Parmelee <jparmele@wildbear.com>
- Date
- Sep 27, 2011, 23:48 UTC
- Message-ID
- <alpine.LNX.2.00.1109271742460.24832@bruno>
Hello all:
Under the present circumstances, and particularly considering the sensitivity of the git code itself, I would suggest that you implement signed detached digital signatures on all release tarballs. Just a crypto hash by itself, however strong, does not protect against man-in-the-middle attacks.
Joseph