1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
|
Received: from sog-mx-4.v43.ch3.sourceforge.com ([172.29.43.194]
helo=mx.sourceforge.net)
by sfs-ml-3.v29.ch3.sourceforge.com with esmtp (Exim 4.76)
(envelope-from <roy@gnomon.org.uk>) id 1UCFTc-0006uZ-AC
for bitcoin-development@lists.sourceforge.net;
Sun, 03 Mar 2013 20:25:44 +0000
Received: from darla.gnomon.org.uk ([93.93.131.22])
by sog-mx-4.v43.ch3.sourceforge.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.76) id 1UCFTa-00073A-Ln
for bitcoin-development@lists.sourceforge.net;
Sun, 03 Mar 2013 20:25:44 +0000
Received: from darla.gnomon.org.uk (localhost.gnomon.org.uk [127.0.0.1])
by darla.gnomon.org.uk (8.14.3/8.14.3) with ESMTP id r23KPGoC072254
(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT);
Sun, 3 Mar 2013 20:25:21 GMT (envelope-from roy@darla.gnomon.org.uk)
X-Virus-Status: Clean
X-Virus-Scanned: clamav-milter 0.95.3 at darla.gnomon.org.uk
Received: (from roy@localhost)
by darla.gnomon.org.uk (8.14.3/8.14.1/Submit) id r23KPGLk072253;
Sun, 3 Mar 2013 20:25:16 GMT (envelope-from roy)
Date: Sun, 3 Mar 2013 20:25:16 +0000
From: Roy Badami <roy@gnomon.org.uk>
To: Gregory Maxwell <gmaxwell@gmail.com>
Message-ID: <20130303202516.GW68379@giles.gnomon.org.uk>
References: <5132558A.8040304@recessionstories.net>
<CABsx9T2yka9vHVttyzTuAEdHtmQSCyAPnJsh1EiwBNoiC24fSg@mail.gmail.com>
<20130303185446.GU68379@giles.gnomon.org.uk>
<CAAS2fgSRYcC4e0E5UiXnLUYZHOkRkvgVdRnmOBWfqcXEKdkgFQ@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <CAAS2fgSRYcC4e0E5UiXnLUYZHOkRkvgVdRnmOBWfqcXEKdkgFQ@mail.gmail.com>
User-Agent: Mutt/1.5.20 (2009-06-14)
X-Spam-Score: -0.6 (/)
X-Spam-Report: Spam Filtering performed by mx.sourceforge.net.
See http://spamassassin.org/tag/ for more details.
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
-0.6 RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
X-Headers-End: 1UCFTa-00073A-Ln
Cc: g@gnomon.org.uk, bitcoin list <bitcoin-development@lists.sourceforge.net>
Subject: Re: [Bitcoin-development] Secure download
X-BeenThere: bitcoin-development@lists.sourceforge.net
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: <bitcoin-development.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/listinfo/bitcoin-development>,
<mailto:bitcoin-development-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=bitcoin-development>
List-Post: <mailto:bitcoin-development@lists.sourceforge.net>
List-Help: <mailto:bitcoin-development-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/bitcoin-development>,
<mailto:bitcoin-development-request@lists.sourceforge.net?subject=subscribe>
X-List-Received-Date: Sun, 03 Mar 2013 20:25:44 -0000
> (The reason for this is that (many? most? all?) CAs verify authority
> by having you place a file at some HTTP path on the domain in
> question.
IME most CAs verify by emailing hostmaster/webaster@ or one of the
contacts in the WHOIS. But you're right, still subject to a MitM.
Still better than nothing though.
I would have suggested an EV cert, but that's more expensive (and
still far from foolproof)
> Basically only helps with the evil hotspot/tor_exit problem.
Also helps protect against DNS spoofing attacks, but yes, you're
right. I should be checking GPG sigs but I'm lazy :-)
roy
|