"Poul-Henning Kamp" <p...@phk.freebsd.dk> writes:
> The only realistic way for the FreeBSD project to implement end-to-end
> trust, is HTTPS with a self-signed cert, distributed and verified
> using the projects PGP-trust-mesh and strong social network.

Your suggestion does not remove implicit and possibly misplaced trust,
it just moves it from one place to another.  Instead of trusting a
certificate authority and DNS, you trust the source of the public key,
and probably also DNS.  As always, it boils down to a) key distribution
is hard and b) what's your threat model?

DES
-- 
Dag-Erling Smørgrav - d...@des.no
_______________________________________________
freebsd-security@freebsd.org mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org"

Reply via email to