Coder Social home page Coder Social logo

GPG signatures for source validation about lurch HOT 5 CLOSED

gkdr avatar gkdr commented on May 20, 2024
GPG signatures for source validation

from lurch.

Comments (5)

NicoHood avatar NicoHood commented on May 20, 2024

Where can we find the digital signatures? I could still not find any, do you upload this package somewhere else too?

from lurch.

gkdr avatar gkdr commented on May 20, 2024

I will not sign code I cannot vouch for. I'll reconsider this once OWS starts signing their code, which I have to include in my source archives.

from lurch.

NicoHood avatar NicoHood commented on May 20, 2024

What? You are the publisher. Signing only helps to verify that the code does not get modified between your, github and the end consumer. It does not give the user any warrenty, unless your license does, which is not the case. So why not help improving the security of the packaging of your security? You are a wise man, you implemented omemo for pidgin, please rethink your decision. Thanks.

from lurch.

gkdr avatar gkdr commented on May 20, 2024

This plugin is just glue code, the main work is done in the submodules, which include libsignal-protocol-c that does most of the crypto. As long as not all the parts are signed, especially the most critical part, I think this is worthless and I'm not willing to deal with PGP for that.
Even if I just sign the resulting tarball (which as I said has to include libsignal-protocol-c), because OWS doesn't employ signatures I have no guarantee that it wasn't modified on the way to my computer (as you said yourself), so I don't want to mislead the users of this plugin.

from lurch.

NicoHood avatar NicoHood commented on May 20, 2024

Imagine someone else wants to include this project in another project. But he will refuse to sign his project, because your project was also not signed. Then nobody would sign any code. Your choice.

And beside this it is also a shame that the signal guys dont sign their code. Even more important than this pidgin addon.

from lurch.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.