From: Lennon Day-Reynolds Date: 2004-06-25T14:00:36+09:00 Subject: Re: rubygems thoughts As a temporary fix, why not have the URLs at which gems can be downloaded be derived from a secure hash (i.e., SHA digest) of the file? It doesn't guarantee that your downloaded gem listing hasn't been affected, but at least a given URL, once distributed as the download location, can easily be checked -- if the actual hash of the downloaded gem is the same as the hash component of the URL, you know that the version you downloaded is the one advertised. Going further, imagine a system with multiple repositories that aggregate some reasonable number of packages -- let's say that ruby-lang.org, rubyforge.org, and sourceforge.net all have public package repositories set up, with a single public key for each repository. If the SHA hashes for each gem are part of the repository listing and URL at which it is downloaded, and the package listing file is signed by the repository administrator(s), then you can have a fairly secure distribution channel without a complex "web of trust". Just get the (presumably well-known and mirrored all over the place) public key for a repository, and you can download any package you like from it without much worry over tampering. Anyone see any obvious attacks or holes? Lennon