[gentoo-user] Re: package download verification

2014-05-09 Thread James
Alan McKinnon gmail.com> writes: > On 08/05/2014 21:13, James wrote: > > So, what a torrent_style tool that uses a distributed hashes/keys > > to check code integrity; is possible? > In one word: git > > Surely the code histogram idea is possible? > Again, git. Wow, this is freaky. I've neve

Re: [gentoo-user] Re: package download verification

2014-05-08 Thread Alan McKinnon
On 08/05/2014 21:13, James wrote: > So, what a torrent_style tool that uses a distributed hashes/keys to check > code integrity; is possible? In one word: git > Surely the code histogram idea is possible? Again, git. An aspect of the git design spec is to try deal with the kind of things you a

[gentoo-user] Re: package download verification

2014-05-08 Thread James
Alan McKinnon gmail.com> writes: > > But why not just use a simple script: > > package.just.downloaded package.just.downloaded.DIGESTS Right now, I perform manual inspections, which are essential only if deemed essential, proned to (visual inspection) mistakes and time consuming. It there is

[gentoo-user] Re: package download verification

2014-05-08 Thread James
Mick gmail.com> writes: > What if the > RNG you use on your PC is either backdoored by Intel (if hardware > generated), or it has such a low entropy that it is trivial to > crack its algorithmic derivatives. Rest easy here. ALL commercial hardware is "backdoor" at the silicon layer, not on

Re: [gentoo-user] Re: package download verification

2014-05-07 Thread Alan McKinnon
On 07/05/2014 16:12, James wrote: > Alan McKinnon gmail.com> writes: > > >>> This is retarded, and I'm too old to do that now, so I went shopping >>> for some script/tool/code to do it for me. In fact, I do not know >>> why the integrity check is not fully integrated into ftp. rsync. >>> or what

Re: [gentoo-user] Re: package download verification

2014-05-07 Thread Mick
On Wednesday 07 May 2014 15:12:53 James wrote: > So please continue the "protage" thread discussion, but also a wider thread > concerning other source downloads. Afterall, *if" you can inject* into > sources, which are then compiled, who checks under the under_garments? Ha! You need to go a few

[gentoo-user] Re: package download verification

2014-05-07 Thread James
Alan McKinnon gmail.com> writes: > > This is retarded, and I'm too old to do that now, so I went shopping > > for some script/tool/code to do it for me. In fact, I do not know > > why the integrity check is not fully integrated into ftp. rsync. > > or whatever the download tool is? > Perhaps I