[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Auto-update (was: Re: SSl challenge - it was fun!)



Sorry if I stuff up; I'm trying for PGP-signed and the PGP is on
a different machine...

-----BEGIN PGP SIGNED MESSAGE-----

Hello Mark <[email protected]>
  and [email protected] (Sherry Mayo)
  and [email protected]

...[asking for an auto-update]...

> I would be extremely wary of this as accepting code written by someone else to
> automatically run on your machine is bad.
...

Why?

I wouldn't say "bad".

I'd say "you need to know what you are doing".

...
> If they do
> not have the expertise, they will hear of it soon enough when others scan the
> offered code.
...

Perhaps there should be a mechanism whereby code offered would be
signed by various parites. When sufficient signatures have collected,
auto-update can proceed.


Yes, no, maybe?

Jiri
- --
If you want an answer, please mail to <[email protected]>.
On sweeney, I may delete without reading!
PGP 463A14D5 (but it's at home so it'll take a day or two)
PGP EF0607F9 (but it's at uni so don't rely on it too much)

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2i

iQCVAwUBMEFmuixV6mvvBgf5AQEkRwP/TUorbtcmElHjWVrxJ8KoTlM0D3/oK4xh
Jh4+QLGaH/aNvI5ehdhPjn+tFXwL/ONS+J/pzO0b2cP9GcM3D6PvtUWxmsTwwaMh
jXkctAPIuO24nb0cAXtcj7LlUe4s5DqIVvkCYi8UrdPXrYEV5DaKti4MYD7oShgC
XMkzzcv55bQ=
=wa8h
-----END PGP SIGNATURE-----