[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
bug#33825: 25.2; , Failing to verify signature for ELPA debbugs package
From: |
Robert Pluim |
Subject: |
bug#33825: 25.2; , Failing to verify signature for ELPA debbugs package |
Date: |
Sun, 30 Dec 2018 13:55:44 +0100 |
Clemens Radermacher <clemens.radermacher@posteo.de> writes:
> On 30.12.18 13:12, Robert Pluim wrote:
>
>> There are 'transparent' proxies which will untar archives and then
>> retar them, resulting in a file that fails signature verification even
>> though the contents are identical. When you then repeat the download,
>> the proxy knows it has previously inspected the file, and thus lets
>> through the original. Using https solves this issue 99% of the time.
>
> That's interesting thanks! For GNU ELPA I use http indeed, because I rely on
> Emacs
> taking care of the verification. I don't understand why those proxies should
> unpack archives though, is that for filtering purposes?
In enlightened democracies they want to see if there is any malware
hiding inside. In other types of countries they're filtering
'undesirable' content. Identifying which type youʼre living in is
becoming harder every day :-)
Robert