2007/9/24, Gilles Chehade <[EMAIL PROTECTED]>: > You can fingerprint the tarballs and compare against the ones on the CD > you bought to support the project ? :-)
I can. But can we agree that packages are not digitally signed, patches are not digitally signed and the methods used to distribute sources online also don't use digital signatures? And that md5/sha1 and pgp are older than OBSD? And to further the flamefest: This is one area where most Linux distros are better. Best Martin