From: Hans Fugal Date: 2004-06-25T06:48:07+09:00 Subject: Re: rubygems thoughts > What I meant is that the more technical part of the problem is easily solved > (using openssl or the upcoming Crypt::RSA), but you still have to build > the web of trust (key signing parties, etc). Which is also what I meant. The hard part here is not the technical, but the social. > >>For example, if I were to release a gem I'd >>like to sign it and provide my public key on the official project >>website, or the fingerprint of it which can be got from a public >>keyserver. That requires a manual check by the user to be of any use, > > > Need not be manual. Either the repository keeps the public keys, some super-AI web scraper figures them out from project home pages, or it has to be manual. My above example was assuming neither repository having public keys nor any other automatic method of public key discovery, so in that case it has to be manual. > You cannot accept libs. + public keys if you haven't verified that the > key was really created by whoever claims it. Right, keyring management would be separate and more carefully controlled. You can go to the extent that Debian does and require physical contact and ID and whatnot, or find some medium that people are comfortable with at a level somewhat below that. (that may be the best you can get though) Accepting the key with the gem wouldn't be any less secure than not signing them at all, of course, although it might give people a false sense of security. > Once you have implemented a signature system and have established the > web of trust, it's makes no sense not to let the end-user verify it > himself: online repositories can be cracked. Yes, if the user has a local cache of the web of trust or relies on external public key servers. But if the user verifies it himself by downloading a public key from the repository there's no benefit because as you said, repositories can be cracked. I think you're right, though, have the verification done on the user's machine. It's more fun that way, anyhow. :-)