Elaine -HFB- Ashton wrote:

> Jeremy Wadsack [[EMAIL PROTECTED]] quoth:
> *>
> *>> A signature by PAUSE is an interesting idea. But it would tell the
> *>> user something different than a signature by a person. While I imagine
> *>> that a sig by GBARR would mean something like: "I have written or at
> *>> least doublechecked the code in this package to be free from malicious
> *>> intent. This is not a warranty." (careful considerations about wording
> *>> pending). A signature of the PAUSE could only mean "These checksums
> *>> were valid at the time of the upload."
> *>
> *>Again, my problem with requiring user signatures is that it complicates
> *>the module distribution process. Unless there's a really EASY way for
> *>people to acquire a signature and apply it to their modules, you're going
> *>to just increase the attrition in Perl developers.
>
> Hang on, don't get too excited just yet as these are just ideas being
> tossed around. ... I need more coffee, but these are simply ideas at this
> point, no need to get your panties in a bunch over letting your imagination
> go in the attempt to find something that really make CPAN a really useable
> space.

Uh.. I didn't mean for that to appear a flame. Perhaps I'm not into the whole
brainstorming idea, but I wanted to bring into light what I considered a
potentially likely response to digital signatures.

Perhaps, I should have been more politic and (more explicitely) suggested a
solution along with my concerns. Specifically, I was thinking:


> We could build some sort of PKI with minimal resources.

And some sort of tie-in to MakeMaker that automatically retrieves the signature
or assignes one if none is already registered. In other-words, making the
signing process vitually transparent to the developer. This would be cool and
allow securing code.


Jeremy Wadsack
Wadsack-Allen Digital Group



Reply via email to