GNU bug report logs - #17625
details of package signing mechanism

Previous Next

Package: emacs;

Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>

Date: Thu, 29 May 2014 03:12:01 UTC

Severity: important

Tags: security

Found in version 24.4.50

Done: Stefan Monnier <monnier <at> iro.umontreal.ca>

Bug is archived. No further changes may be made.

Full log


Message #69 received at 17625 <at> debbugs.gnu.org (full text, mbox):

From: Glenn Morris <rgm <at> gnu.org>
To: Stefan Monnier <monnier <at> iro.umontreal.ca>
Cc: 17625 <at> debbugs.gnu.org
Subject: Re: bug#17625: 24.4.50;
 All installed packages marked "unsigned", no archive listed
Date: Mon, 23 Jun 2014 14:12:49 -0400
PS I won't pretend to know what I am talking about here, but I worry
that the combination of automated package signing and automated key
installation will make this package-signing feature not worth very much
in practice.

Eg if clients automatically (even with prompting) install public keys
from the package server the first time they connect, then this leaves
zero protection against a man-in-the-middle attack. I connect to
something that says it is elpa.gnu.org and install the key it offers.
I have no way to know if it really is elpa.gnu.org.

(With elpa.gnu.org we should distribute the public key in the Emacs etc/
directory.)




This bug report was last modified 10 years and 236 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.