[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-security] RE: 'On my Soap Box'



> your site reminded me that cobalt does not publish the md5sums 
> for its pkg files on the website. Being super-ultra paranoid 
> like myself, this extra layer of verification would be a welcome 
> addition.

I'd just like to point out that if the cobalt distribution server
was comprimised and the pkg files were tampered with, its a fair
assumption that the webpage would be altered to reflect the new
altered MD5 sums.