View Single Post
  #3 (permalink)  
Old June 6th, 2003
zimon zimon is offline
Disciple
 
Join Date: May 29th, 2003
Posts: 14
zimon is flying high
Exclamation RPM packages are not GPG signed

http://sourceforge.net/project/showf...?group_id=4467

So, whoever packages them, could GPG sign the rpm packages.

Currently a man in the middle can switch on the fly the packages being downloaded from mirrors and noone would notice.

http://www.rpm.org/max-rpm/s1-rpm-pg...-packages.html<http://www.rpm.org/max-rpm/s1-rpm-pg...-packages.html

To the main topic, I think it is sometimes good to protect "stupid" users for not running some program, especially p2p, as root.

Also while am at this.
CVS version currently seems to report a version of the servant just with "0.92u". Maybe somehow there should/could be a date of the latest changes in the version string.

I don't know, but seems like at least v0.92b and also 0.92c ultrapeers do not like to connect with v0.92u. (all gtk-gnutellas)
Reply With Quote