Hi Hasan,

To be clear, Jonathan has so far posted to the list and not facilitated any 
pirates!

To summarise what is going on (and separate from any tedious license 
discussions) - in the interests of preventing DXPedition piracy, some people 
are playing with the new binaries and have surmised that they use an insecure 
approach to keysigning which *could* facilitate pirates.

Identity and keysigning is a solved problem - we use free software for identity 
verification and proof of work in the open as part of our chain of trust in 
Debian. This extends to Ubuntu and other Linux distributions in our family, 
including the popular Raspberry Pi.
When I upload wsjt-x to the Debian archives, this system is used to verify it 
is absolutely me and it'll reject all imitators.

To keep things moving as they are & civil while facilitating the upcoming 
dxpedition testing this cool feature, no one has released any code that would 
facilitate pirates but have instead suggested that development in the open with 
discussion around solving the problem in a manner that allows many to use the 
service would be best.

Cheers!

-- 
  Hibby
  Debian Developer
  Packet Radioist
  MM0RFN

On Wed, 24 Jul 2024, at 2:02 PM, Hasan N0AN via wsjt-devel wrote:
> Yes, congratulations are in order. You have now made it easy for the Pirates, 
> before it was somewhat more difficult.
> Way to go.
> Hasan
> 
> 
> On Wed, Jul 24, 2024 at 7:31 AM Jonathan McComb via wsjt-devel 
> <wsjt-devel@lists.sourceforge.net> wrote:
>> Hasan,
>> 
>> Did you actually take the time to read **and understand** the blog post I 
>> linked, and the contents of the similar discussions (linked below) regarding 
>> the superfox binaries in the mailing list?
>> 
>> https://sourceforge.net/p/wsjt/mailman/wsjt-devel/thread/ZoMmzGysLjXJ5B2O%40msg.df7cb.de/#msg58790775
>> 
>> https://sourceforge.net/p/wsjt/mailman/wsjt-devel/thread/CAH3sL-bVdgxXz44T1U%2BCVvi9rXCfwur%2BoM-ws7yKcZkAw1u3Fw%40mail.gmail.com/#msg58797048
>> 
>> Jonath**_a_**n, GI3JMC
>> 
>> On Wed, Jul 24, 2024 at 12:59 PM Hasan N0AN <hbasri.schie...@gmail.com> 
>> wrote:
>>> Jonathon,
>>> Then don't use SuperFox
>>> Hasan
>>> 
>>> 
>>> On Wed, Jul 24, 2024 at 5:25 AM Jonathan McComb via wsjt-devel 
>>> <wsjt-devel@lists.sourceforge.net> wrote:
>>>> https://sprocketfox.io/xssfox/2024/07/24/superflawed/
>>>> 
>>>> The Superfox mode uses security by obscurity, (which is never a good 
>>>> thing) by failing to publish any source code for the dedicated superfox 
>>>> binaries to allow for peer review. It is exceptionally misguided.
>>>> 
>>>> Amateur Radio should be available to everyone to use, without having 
>>>> software functions/features hidden behind a gatekeeping organisation 
>>>> (Northern California DX Foundation).  A more cynical person would surmise 
>>>> that this is a first step to making the feature a paid one.
>>>> 
>>>> Jonathan, GI3JMC
>>>> 
>>>> 
>>>> _______________________________________________
>>>> wsjt-devel mailing list
>>>> wsjt-devel@lists.sourceforge.net
>>>> https://lists.sourceforge.net/lists/listinfo/wsjt-devel
>> _______________________________________________
>> wsjt-devel mailing list
>> wsjt-devel@lists.sourceforge.net
>> https://lists.sourceforge.net/lists/listinfo/wsjt-devel
> 
> _______________________________________________
> wsjt-devel mailing list
> wsjt-devel@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/wsjt-devel
> 
_______________________________________________
wsjt-devel mailing list
wsjt-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/wsjt-devel

Reply via email to