From: Charlie Somerville Date: 2013-02-04T07:20:47+09:00 Subject: [ruby-core:51830] SSL for ftp.ruby-lang.org --510ee2a4_440badfc_88 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Content-Disposition: inline In light of the recent security issues with RubyGems, I think it would be a good idea to look at how Ruby itself is distributed. Currently the main place to download Ruby source distributions is http://ftp.ruby-lang.org/. These downloads are run over cleartext HTTP and are unauthenticated. SSL should be considered for this host so users downloading Ruby can have some assurance that the distribution has not been tampered with. I think eventually SSL should be mandatory, although I'm not sure if this would break software like RVM. Cheers, Charlie --510ee2a4_440badfc_88 Content-Type: text/html; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline
In light of the recent security issues with RubyGems= , I think it would be a good idea to look at how Ruby itself is distribut= ed.

Currently the main place to dow= nload Ruby source distributions is http://ftp.ruby-lang.org/.
<= br>
These downloads are run over cleartext HTTP and are unauthe= nticated.

SSL should be considered for this host= so users downloading Ruby can have some assurance that the distribution = has not been tampered with.

I think eventually S= SL should be mandatory, although I'm not sure if this would break softwar= e like RVM.

Cheers,

Cha= rlie
--510ee2a4_440badfc_88--