[haiku-development] Re: Design for signed packages

  • From: Fredrik Holmqvist <fredrik.holmqvist@xxxxxxxxx>
  • To: haiku-development <haiku-development@xxxxxxxxxxxxx>
  • Date: Fri, 28 Mar 2014 10:23:16 +0100

2014-03-28 4:00 GMT+01:00 waddlesplash <ajcsweb@xxxxxxxxx>:
> Let me be frank here: I am not opposed to signed packages. I am opposed to
> too much paranoia. Simple signed packages, as in "I guarantee this is in the
> state X Corp created it in" and not "Haiku, Inc tested this and verified
> that it both comes from X Corp and is virus-free." The first is good, the
> second is paranoia IMO.

I'm not sure if this is really helpful or leading the discussion
forward. At some point we need to discuss what should be signed and
what guarantees we make, but this thread is about the design of a
signed package format. Also the wording could have been friendlier,
I'd really hate this becoming another elitist community.

Please keep posts on topic.


Fredrik Holmqvist, TQH

Other related posts: