Showing content from http://mail.python.org/pipermail/python-dev/attachments/20150403/017d0759/attachment.html below:
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=windows-1256">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div>
<div style="font-family:Calibri,sans-serif; font-size:11pt">The thing is, that's exactly the same goodness as Authenticode gives, except everyone gets that for free and meanwhile you're the only one who has admitted to using GPG on Windows :)<br>
<br>
Basically, what I want to hear is that GPG sigs provide significantly better protection than hashes (and I can provide better than MD5 for all files if it's useful), taking into consideration that (I assume) I'd have to obtain a signing key for GPG and unless
there's a CA involved like there is for Authenticode, there's no existing trust in that key.<br>
<br>
Cheers,<br>
Steve<br>
<br>
Top-posted from my Windows Phone</div>
</div>
<div dir="ltr">
<hr>
<span style="font-family:Calibri,sans-serif; font-size:11pt; font-weight:bold">From:
</span><span style="font-family:Calibri,sans-serif; font-size:11pt"><a href="mailto:mal@egenix.com">M.-A. Lemburg</a></span><br>
<span style="font-family:Calibri,sans-serif; font-size:11pt; font-weight:bold">Sent:
</span><span style="font-family:Calibri,sans-serif; font-size:11pt">ý4/ý3/ý2015 10:55</span><br>
<span style="font-family:Calibri,sans-serif; font-size:11pt; font-weight:bold">To:
</span><span style="font-family:Calibri,sans-serif; font-size:11pt"><a href="mailto:Steve.Dower@microsoft.com">Steve Dower</a>;
<a href="mailto:larry@hastings.org">Larry Hastings</a>; <a href="mailto:python-dev@python.org">
Python Dev</a>; <a href="mailto:python-committers@python.org">python-committers</a></span><br>
<span style="font-family:Calibri,sans-serif; font-size:11pt; font-weight:bold">Subject:
</span><span style="font-family:Calibri,sans-serif; font-size:11pt">Re: [python-committers] [Python-Dev] Do we need to sign Windows files with GnuPG?</span><br>
<br>
</div>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On 03.04.2015 19:35, Steve Dower wrote:<br>
>> My Windows development days are firmly behind me. So I don't really have an<br>
>> opinion here. So I put it to you, Windows Python developers: do you care about<br>
>> GnuPG signatures on Windows-specific files? Or do you not care?<br>
> <br>
> The later replies seem to suggest that they are general goodness that nobody on Windows will use. If someone convinces me (or steamrolls me, that's fine too) that the goodness of GPG is better than a hash then I'll look into adding it into the process. Otherwise
I'll happily add hash generation into the upload process (which I'm going to do anyway for the ones displayed on the download page).<br>
<br>
FWIW: I regularly check the GPG sigs on all important downloaded<br>
files, regardless of which platform they target, including the<br>
Windows installers for Python or any other Windows installers<br>
I use which provide such sigs.<br>
<br>
The reason is simple:<br>
The signature is a proof of authenticity which is not bound to<br>
a particular file format or platform and before running .exes<br>
it's good to know that they were built by the right people and<br>
not manipulated by trojans, viruses or malicious proxies.<br>
<br>
Is that a good enough reason to continue providing the GPG<br>
sigs or do you need more proof of goodness ? ;-)<br>
<br>
-- <br>
Marc-Andre Lemburg<br>
eGenix.com<br>
<br>
Professional Python Services directly from the Source<br>
>>> Python/Zope Consulting and Support ... <a href="http://www.egenix.com/">
http://www.egenix.com/</a><br>
>>> mxODBC.Zope.Database.Adapter ... <a href="http://zope.egenix.com/">
http://zope.egenix.com/</a><br>
>>> mxODBC, mxDateTime, mxTextTools ... <a href="http://python.egenix.com/">
http://python.egenix.com/</a><br>
________________________________________________________________________<br>
<br>
::: Try our new mxODBC.Connect Python Database Interface for free ! ::::<br>
<br>
<br>
eGenix.com Software, Skills and Services GmbH Pastor-Loeh-Str.48<br>
D-40764 Langenfeld, Germany. CEO Dipl.-Math. Marc-Andre Lemburg<br>
Registered at Amtsgericht Duesseldorf: HRB 46611<br>
<a href="http://www.egenix.com/company/contact/">http://www.egenix.com/company/contact/</a><br>
</div>
</span></font>
</body>
</html>
RetroSearch is an open source project built by @garambo
| Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4