http subversion URLs should be discontinued in favor of https URLs

Dag-Erling Smørgrav des at des.no
Tue Dec 12 12:08:06 UTC 2017


"Poul-Henning Kamp" <phk at phk.freebsd.dk> writes:
> The only realistic way for the FreeBSD project to implement end-to-end
> trust, is HTTPS with a self-signed cert, distributed and verified
> using the projects PGP-trust-mesh and strong social network.

Your suggestion does not remove implicit and possibly misplaced trust,
it just moves it from one place to another.  Instead of trusting a
certificate authority and DNS, you trust the source of the public key,
and probably also DNS.  As always, it boils down to a) key distribution
is hard and b) what's your threat model?

DES
-- 
Dag-Erling Smørgrav - des at des.no


More information about the freebsd-security mailing list