Good evening folks, in the past I witnessed bits and pieces of attempts to increase the infrastructure userside, but, unless I'm mistaken, there's still room for improvement.
Since a couple of years we have the webrsync-gpg FEATURE, which enables automatic verification of the portage tree, when updated via webrsync. We also have mandatory signing via gpg of packages, news items and (I strongly suspect) GLSAs for maintainers. Yet, there's not checking mechanism whatsoever in portage. Now my question: are there plans existing on how to improve this situation? Any project that might be involved with such plans? In particular, my question is with respect to - automatic verififcation of the gpg-signatures provided when syncing via git - development of a verification scheme that works just as well with rsync - on the threat-assessment side: are there dangers involved, apart from a mitm-attack between the (rsyncing) end-user and a mirror or a mirror and the main servers? Thank you for your time. With kind regards, tomboy64
signature.asc
Description: OpenPGP digital signature
