Re: kernel.org status: establishing a PGP web of trust

From: Krzysztof Halasa
Date: Thu Oct 06 2011 - 13:06:02 EST


Adrian Bunk <bunk@xxxxxxxxx> writes:

> If you just want to be sure that patch number 100 comes from the same
> person as the 99 patches before you could do that without key signing
> (require signed patches and check that all 100 patches were signed by
> the same key).

This leaves room for MITM attacks. The attacked can remove the original
signature and add his own.
--
Krzysztof Halasa
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/