comp.lang.ada
 help / color / mirror / Atom feed
From: kilgallen@eisner.decus.org (Larry Kilgallen)
Subject: Re: Compiling gnat into gcc-2.8.0
Date: 1998/02/27
Date: 1998-02-27T00:00:00+00:00	[thread overview]
Message-ID: <1998Feb27.103817.1@eisner> (raw)
In-Reply-To: m3yayxgl71.fsf@fred.muc.de


In article <m3yayxgl71.fsf@fred.muc.de>, Andi Kleen <ak@muc.de> writes:
> dewar@merv.cs.nyu.edu (Robert Dewar) writes:
> 
>> 
>> There is of course no technical basis for such a claim. It probably stems
>> from the concern that if the sources are available, then anyone can modify
>> them. This is of course true, and there is no doubt that getting a version
>> of GNAT that has been modified by person or persons unknown, or may have
>> been modified in such a way, is potentially risky. We always warn people
>> that one of the issues in using the public version is that there is no
>> guarantee that we can provide that what you get corresponds to what we
>> initially distributed. It is most unlikely that anyone would have tampered
>> with the public distribution, but it is entirely out of our control.
> 
> One way around this would be if ACT would publish PGP signatures of the
> binary and source tar balls of the public gnat releases. Of course there
> is still a lower risk that someone changes the signatures, but assuming
> the web of trust works and that the signatures are widely published (e.g.
> posted to Usenet etc.) this is a rather save choice.

If I were an ACT customer, I would prefer the first priority be to sign
CDROms distributed to paying customers (or is that done already?).

Some of the paranoid would want the signature to be hierarchy-based
and tied to a root from GTE or Verisign rather than the "Web of Trust"
method of PGP.  The nice thing about digital signatures, however, is that
you can sign the same thing several times to satisfy various constituencies.

Larry Kilgallen




  reply	other threads:[~1998-02-27  0:00 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
1998-02-25  0:00 Compiling gnat into gcc-2.8.0 Kevin Taylor
1998-02-26  0:00 ` Stephen Leake
1998-02-26  0:00   ` Robert Dewar
1998-02-27  0:00   ` Markus Kuhn
1998-02-27  0:00     ` Richard Kenner
1998-03-01  0:00       ` Trusting GNAT for security software Markus Kuhn
1998-03-01  0:00         ` Robert Dewar
1998-03-01  0:00           ` Larry Kilgallen
1998-03-01  0:00             ` Robert Dewar
1998-03-02  0:00               ` Larry Kilgallen
1998-03-02  0:00             ` Andi Kleen
1998-03-02  0:00               ` Larry Kilgallen
1998-02-27  0:00     ` Compiling gnat into gcc-2.8.0 Robert Dewar
1998-02-27  0:00       ` Andi Kleen
1998-02-27  0:00         ` Larry Kilgallen [this message]
1998-02-27  0:00           ` Robert Dewar
1998-02-26  0:00 ` Simon Wright
1998-02-26  0:00   ` Robert Dewar
replies disabled

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox