Re: Trust in the Debian Build Process

>>"Torsten" == Torsten Landschoff <t.landschoff@gmx.net> writes:

 Torsten> What can we do against this? I guess most of the users at
 Torsten> most verify their packages using the Debian keyring from the
 Torsten> mirror/cd, so somebody could even circumvent the digital
 Torsten> signature by changing the key of a developer in the
 Torsten> keyring...

	Correct. We do not have a serious security policy in place,
 just one that is ``secure enough''.  Ian Jackson once proposed a
 formal security fgramework (involving three interlocking highly
 secure keys, and a signing key), with which every package would be
 detached signed, but we never got around to implementing it

