From: "Mauricio Fernández" Date: 2004-06-25T17:59:28+09:00 Subject: Re: rubygems thoughts On Fri, Jun 25, 2004 at 02:00:36PM +0900, Lennon Day-Reynolds wrote: > If the SHA hashes for each gem are part of the repository > listing and URL at which it is downloaded, and the package listing > file is signed by the repository administrator(s), then you can have a > fairly secure distribution channel without a complex "web of trust". > Just get the (presumably well-known and mirrored all over the place) > public key for a repository, and you can download any package you like > from it without much worry over tampering. This sort of centralized system is the easiest solution (I'm soon implementing it :), but it requires that the repository maintainers actively monitor the packages they accept, to make sure they're not distributing trojans. RubyGems is built on the idea that upstream developers should do the packaging themselves [1]: RubyGems' developers only hack the installer itself, they're not responsible for the gems distributed from their repos. Some more info about the advantages of having a 3rd party packaging team can be found at http://rpa-base.rubyforge.org/wiki/wiki.cgi?Rpa_FAQ . (1) and implicitly that all gems out there are OK (that is, packaged correctly and non-malicious), since there's no control/QA process. -- Running Debian GNU/Linux Sid (unstable) batsman dot geo at yahoo dot com * SynrG notes that the number of configuration questions to answer in sendmail is NON-TRIVIAL -- Seen on #Debian