Foiling MITM attacks on source and ports trees

Mel fbsd.questions at rachie.is-a-geek.net
Tue Jan 6 07:58:41 UTC 2009


On Saturday 03 January 2009 03:45:11 Matthew Seaman wrote:

> [*] Buying a high security cert from the likes of Verisign or OpenSRS would
> set you back about £800 p.a. and it would probably be necessary to use
> someone like the FreeBSD Foundation as an appropriate body to own the cert.

<OT>
I would actually trust a self-signed cert by the FreeBSD security officer, 
more then one by Verisign. Power hungry companies like Verisign are more 
succeptable to corruption then the entity I want to have or already a 
relationship with in the first place.
</OT>
-- 
Mel

Problem with today's modular software: they start with the modules
    and never get to the software part.


More information about the freebsd-questions mailing list