[Haskell-cafe] Enhancing the security of hackage

2010-12-09 Thread Ketil Malde
Vincent Hanquez t...@snarc.org writes: You might have misunderstood what I was talking about. I'm proposing signing on the hackage server on reception of the package, Okay, fair enough. You can't *enforce* this, of course, since I might work without general internet access but a local mirror,

Re: [Haskell-cafe] Enhancing the security of hackage

2010-12-09 Thread Lally Singh
On Thu, Dec 9, 2010 at 7:04 AM, Ketil Malde ke...@malde.org wrote: Vincent Hanquez t...@snarc.org writes: You might have misunderstood what I was talking about. I'm proposing signing on the hackage server on reception of the package, Okay, fair enough.  You can't *enforce* this, of course,

Re: [Haskell-cafe] Enhancing the security of hackage

2010-12-09 Thread Ivan Lazar Miljenovic
On 9 December 2010 23:04, Ketil Malde ke...@malde.org wrote: [snip] This way, somebody is likely to actually *notice* when some evil person uploads a trojan mtl or bytestring or whatever.  The downside is more mail, and the people who run Hackage have been wary about this.  So perhaps even