Re: Reflections on Trusting Trust
Kris Kennaway <kris@obsecurity.org> wrote:
> On Tue, Nov 29, 2005 at 06:07:29PM -0800, Colin Percival wrote:
>> If we're going to sign anything, we need to ensure not just that we're
>> signing what we think we're signing, but also that we're signing what the
>> *end users* think that we're signing.
>
> Seems to me that ignorance and a false sense of security is bad
> wherever it appears, so all we can do is try our best to educate users
> about what they're getting.
By printing a nice text every time someone installs a signed package? Noisy
and annoying, but because of this nobody is allowed to say they didn't
knowed about it.
Bye,
Alexander.
--
http://www.Leidinger.net Alexander @ Leidinger.net: PGP ID = B0063FE7
http://www.FreeBSD.org netchild @ FreeBSD.org : PGP ID = 72077137
HARTLEY'S SECOND LAW:
Never sleep with anyone crazier than yourself.
My corollary:
The completely psychotic have all the fun.
_______________________________________________
freebsd-security@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
討論串 (同標題文章)
完整討論串 (本文為第 25 之 36 篇):