bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-18 Thread Ludovic Courtès
Hi all, Carlo Zancanaro skribis: > I'm not convinced there's much value to add anything beyond the > signatures, and I think there is some cost. Having multiple > verification options makes the download page more confusing (by > providing more choices to do the same thing), and may make it less

bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-10 Thread bo0od
> In this instance, the hash provides no > significant additional value over the signature. What you said is true, Only thing i would see it useful when there is an attack on PGP but not necessary can be produced as well on the same time on SHA512 like collision attack or so (nothing at the mom

bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-09 Thread bo0od
> Which implies that the signatures are sufficient, right? Well this is simple question but the answer is sorta deeper, So i will answer with yes and no: yes signatures are sufficient but signatures with PGP has problems, In the suggestion above i didnt suggest to diverse the signing methods

bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-08 Thread Carlo Zancanaro
On 9 April 2021 3:34:20 am AEST, bo0od wrote: >This is nicely written by Qubes documentation: > >https://www.qubes-os.org/security/verifying-signatures/ From that page: > If you’ve already verified the signatures on the ISO directly, then verifying > digests is not necessary. Which implies

bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-08 Thread bo0od
This is nicely written by Qubes documentation: https://www.qubes-os.org/security/verifying-signatures/ Leo Famulari: On Wed, Apr 07, 2021 at 05:42:40AM +, bo0od wrote: Hi There, I see there is only .sig provided: https://guix.gnu.org/en/download/ Its better to provide more than one way

bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-08 Thread Leo Famulari
On Wed, Apr 07, 2021 at 05:42:40AM +, bo0od wrote: > Hi There, > > I see there is only .sig provided: > > https://guix.gnu.org/en/download/ > > Its better to provide more than one way of verification e.g: Why?

bug#47634: Accompany .asc and .DIGESTS keys for the ISO

2021-04-07 Thread bo0od
Hi There, I see there is only .sig provided: https://guix.gnu.org/en/download/ Its better to provide more than one way of verification e.g: Qubes: https://www.qubes-os.org/downloads/ Whonix: https://www.whonix.org/wiki/VirtualBox/XFCE ...etc ThX!