Skip to content
This repository has been archived by the owner on Oct 23, 2020. It is now read-only.

Make downloading of binary packages secure #46

Open
hellais opened this issue Sep 21, 2012 · 1 comment
Open

Make downloading of binary packages secure #46

hellais opened this issue Sep 21, 2012 · 1 comment

Comments

@hellais
Copy link
Contributor

hellais commented Sep 21, 2012

Looking at https://github.com/globaleaks/APAF/blob/master/apaf/build.py, it appears that the download uses urrlib that does not verify SSL certificates and the function for verifying the signature of the binary always returns true.

I suggest we have the public key fingerprint of the people signing packages hardcoded inside of the source (or in some other part of the software, but we ship with it).

We should also bundle a set of SSL roots that are trustworthy and be sure that proper SSL verification is being done.

@fpietrosanti
Copy link
Contributor

Also related to:

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants