gnu-arch-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Gnu-arch-users] (volunteers?) crypto signatures for arch


From: Charles Duffy
Subject: Re: [Gnu-arch-users] (volunteers?) crypto signatures for arch
Date: Sun, 07 Dec 2003 16:38:09 -0600

On Sun, 2003-12-07 at 14:49, Tom Lord wrote:
> That's not true.  It can verify the incoming data, protect it, and
> discard the original tar-ball and signature.

How does it "protect it"? By applying its own signature? Since the key
used to create that new signature is necessarily stored on the server,
how does one prevent an attacker from misusing said key after
compromising said server?





reply via email to

[Prev in Thread] Current Thread [Next in Thread]