Re: Security flaw caused by RC sigs [was: Release policy question]
From: Christian Stork <cstork_at_ics.uci.edu>
Date: 2006-02-02 23:45:56 CET
On Thu, Feb 02, 2006 at 04:49:24PM -0500, Greg Hudson wrote:
> The tarball does contain the version number inside, so Good Company will
> If we've reused the version number from a testing tarball, that would be
OK, that makes sense then wrt to the testing tarballs (and should be
But what's the point of the RC signatures then? For secure communication
-- Chris Stork <> Support eff.org! <> http://www.ics.uci.edu/~cstork/ OpenPGP fingerprint: B08B 602C C806 C492 D069 021E 41F3 8C8D 50F9 CA2F --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscribe@subversion.tigris.org For additional commands, e-mail: dev-help@subversion.tigris.orgReceived on Thu Feb 2 23:46:24 2006 |
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.