> How do you get a copy of cabal while making sure that somebody hasn't
> MITMed you and replaced the PGP key?

You don't. Somewhere, you just have to trust that nothing went awry.
The best thing to do is just to make it as difficult as possible for an
attacker to be successful - make the PGP keys widely known and have a
lot of people sign them.

-- 
Michael Walker (http://www.barrucadu.co.uk)

Attachment: signature.asc
Description: PGP signature

_______________________________________________
Haskell-Cafe mailing list
Haskell-Cafe@haskell.org
http://www.haskell.org/mailman/listinfo/haskell-cafe

Reply via email to