From: "Mauricio Fernández" Date: 2004-06-25T04:21:47+09:00 Subject: Re: rubygems thoughts On Fri, Jun 25, 2004 at 02:28:09AM +0900, Hans Fugal wrote: > >There's unfortunately no security mechanism in RubyGems atm.; this is > >somewhat difficult due to RubyGems "distributed" nature, where the > >packaging work is pushed down to upstream developers, so even if gem > >signatures were implemented, building the web of trust could take some > >time. > > > > A good start would be working in signatures and letting people do with > that whatever seems natural. What I meant is that the more technical part of the problem is easily solved (using openssl or the upcoming Crypt::RSA), but you still have to build the web of trust (key signing parties, etc). >For example, if I were to release a gem I'd > like to sign it and provide my public key on the official project > website, or the fingerprint of it which can be got from a public > keyserver. That requires a manual check by the user to be of any use, Need not be manual. > but once the infrastructure is there other things can evolve, like some > repositories would have an upload system where developers must sign the > gem and they are allowed to upload with their signature for a set of > packages. Packages can be uploaded by possibly more than one developer. > The repository provides, along with the gems, a keyring of the public ===================== You cannot accept libs. + public keys if you haven't verified that the key was really created by whoever claims it. > keys. The client downloads a package and checks its signature against > that keyring. Or maybe the client doesn't even need to verify, because Once you have implemented a signature system and have established the web of trust, it's makes no sense not to let the end-user verify it himself: online repositories can be cracked. -- Running Debian GNU/Linux Sid (unstable) batsman dot geo at yahoo dot com Thinking is dangerous. It leads to ideas. -- Seen on #Debian