Re: Dave Page's PGP key

From: "Dave Page" <dpage(at)vale-housing(dot)co(dot)uk>
To: "Peter Eisentraut" <peter_e(at)gmx(dot)net>, <pgadmin-hackers(at)postgresql(dot)org>
Subject: Re: Dave Page's PGP key
Date: 2006-07-22 09:57:52
Message-ID: E7F85A1B5FF8D44C8A1AF6885BC9A0E40154C130@ratbert.vale-housing.co.uk
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgadmin-hackers

> -----Original Message-----
> From: pgadmin-hackers-owner(at)postgresql(dot)org
> [mailto:pgadmin-hackers-owner(at)postgresql(dot)org] On Behalf Of
> Peter Eisentraut
> Sent: 22 July 2006 02:07
> To: pgadmin-hackers(at)postgresql(dot)org
> Subject: [pgadmin-hackers] Dave Page's PGP key
>
> Either I'm doing something wrong or Dave Page's PGP key that
> is used to
> sign pgAdmin releases does not have any signatures on it. That would
> make the process of verifying the releases rather impossible.

In order to compromise those file signatures, an attacker would have to
replace my public key on the pgAdmin SVN repo (from where it propagates
out to the webservers), and somehow replace the copy on the keyservers
(which you also checked right?), in addition to rewriting each signature
on a compromised file.

Compare that to the md5sum's that Greg(?) produces of the server which
are produced some time after the build based on whatever source Greg
uses to get the tarballs which may have already been compromised (I
generate the sigs as I build the releases). There is also no way to
verify the authenticity of the sums, except checking directly with Greg.

So no, I don't believe it's impossible to verify the pgAdmin releases -
we in fact have a mechanism that's far more secure than the more common
practice of file checksumming albeit not quite as watertight as it could
be. It would be good to get some signatures on my key, but up until very
recently the only names I could have got are ones that you would never
have heard of, and thus would not have proved anything. I must speak
with Greg about that...

Regards, Dave.

In response to

Responses

Browse pgadmin-hackers by date

  From Date Subject
Next Message Peter Eisentraut 2006-07-22 12:17:13 Re: Dave Page's PGP key
Previous Message Peter Eisentraut 2006-07-22 01:06:44 Dave Page's PGP key