Jeremy Wadsack [[EMAIL PROTECTED]] quoth: *> *>> A signature by PAUSE is an interesting idea. But it would tell the *>> user something different than a signature by a person. While I imagine *>> that a sig by GBARR would mean something like: "I have written or at *>> least doublechecked the code in this package to be free from malicious *>> intent. This is not a warranty." (careful considerations about wording *>> pending). A signature of the PAUSE could only mean "These checksums *>> were valid at the time of the upload." *> *>Again, my problem with requiring user signatures is that it complicates *>the module distribution process. Unless there's a really EASY way for *>people to acquire a signature and apply it to their modules, you're going *>to just increase the attrition in Perl developers. Hang on, don't get too excited just yet as these are just ideas being tossed around. However, the PGP signature is an idea I ran across on c.l.p.m. a few months back when someone was wondering what good the MD5 checksums were and what, if anything, could be stronger. Now, the only person who is going to know the code intimately is going to be the developer of a particular module and CPAN certainly can't spend calendar years wading through code to be sure that modules haven't been tampered with at any point in time. It doesn't have to be a burden to the developer and I'm tired of hearing people say "CPAN sucks and doesn't have QA" out of one orifice and "Don't burden me out of the other". Compromises must be made here. So, I like the idea of it being optional, but I think there are ways to make it agreeable to the CPAN developers and make it an attractive option to sign their code cryptographically so as to reassure the user that the code is, at the very least, marginally secure. We could build some sort of PKI with minimal resources. I need more coffee, but these are simply ideas at this point, no need to get your panties in a bunch over letting your imagination go in the attempt to find something that really make CPAN a really useable space. btw - Randy Kobes, Ulrich and Paul Schinder might have some very useful input should someone care to invite them here and they are willing to join in. e.

