![]() |
|
#26
|
|||
|
|||
|
Quote:
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#27
|
|||
|
|||
|
Quote:
That's easily deterred by having the developer sign his packages and source code. Once you download it you check to make sure it is signed by the correct key. Of course, you need to have a way to find out what the correct key is in the first place, but that's easy enough to do with the Web of Trust (or with a phone call to the developer, etc). There's no need to send the package back to him for verification if he is signing them in the first place. Quote:
Nothing's stopping them. A self-signed cert simply means you generated and signed the cert yourself (no third-party involvement). Of course, this means it will be hard to tell whether it is a legitimate cert from the website owner of if you're being MITM'ed. Most of the time self-signed certs are TOFU (Trust on First Use). Add-ons like Convergence can help verify self-signed certs by checking the cert from various machines around the world. If they match, then there is a high probability it is a good cert (it would take a powerful entity to pull off a MITM on that scale). |
|
#28
|
|||
|
|||
|
Quote:
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come. |
|
#29
|
||||
|
||||
|
Quote:
Compiler/bin's? Yes, if they produce identical results. OS/vendor/hw? Yes if NOT online. Quote:
You bet! So be careful! Stay offline. They all are -- like another poster said --- "surveillance friendly"! Quote:
I agree! I don't however see why one should no be looking at the best that can be done! Draw a baseline in the sand then stay a confortable distance behind. We are just chatting on a forum and not brainstorming over national security strategies!!
__________________
Be good and do disturb! Not disturbed enough yet. danleonida-at-yahoo-dot-comm |
|
#30
|
||||
|
||||
|
Quote:
I'm at a loss here because I don't know enough about digital signitures and therefore I don't fully understand what's to stop Eve from just copying it! I'll look it up, though! Do you happen to remember when Zimmermann stopped using the authentication network and why?
__________________
Be good and do disturb! Not disturbed enough yet. danleonida-at-yahoo-dot-comm |
|
#31
|
|||
|
|||
|
Quote:
box do you mean in general or just for this particular business? If you mean in general then I completely disagree. Many quality and reliable services have been provided that were not of the profit motive.
__________________
Lew Win7 64-Sandboxie Paid- Malwarebytes and SAS On Demand Paid-VMware Shadow Defender-Emisoft AntiMalware-WFC |
|
#32
|
||||
|
||||
|
Quote:
Quote:
I did the looking up and I think I got it now! Thx. Q: Why in the world did Zimmermann use the cumbersome authentication network when he released PGP in the 90s? Hashing and private/public keys were well known then! I still have a nagging feeling I'm missing something! Help anyone?!
__________________
Be good and do disturb! Not disturbed enough yet. danleonida-at-yahoo-dot-comm |
|
#33
|
||||
|
||||
|
Quote:
Well... The nagging feeling is still is still there, so I'm 'nagging' you all! :>) The question is the same as in post above: "Why in the world did Zimmermann use the cumbersome authentication network when he released PGP in the 90s? Hashing and private/public keys were well known then!" [Edit.1]Possible answer in my mind, at least, is that an 'authentication network' is more secure than a digital signature!! Am I correct in that? [/Edit.1]
__________________
Be good and do disturb! Not disturbed enough yet. danleonida-at-yahoo-dot-comm Last edited by danleonida : September 13th, 2012 at 01:53 PM. |
|
#34
|
||||
|
||||
|
Quote:
There are great free quality software out there, I use dozens of those tools myself but product continuation and development is not guaranteed without a business model. I know lots of excellent privacy projects that have become abandonware or is hardly updated. For example, I don't think it is an accident that my excellent PCTools firewall free version was discontinued 2 years ago.
__________________
My security blog: http://www.hacker10.com Last edited by box750 : September 13th, 2012 at 02:32 PM. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|