[Haskell-cafe] [Security] Put haskell.org on https

Changaco changaco at changaco.net
Mon Oct 29 00:34:08 CET 2012


On Sun, 28 Oct 2012 17:07:24 -0400 Patrick Hurst wrote:
> How do you get a copy of cabal while making sure that somebody hasn't MITMed you and replaced the PGP key?

Ultimately it is a DNS problem. To establish a secure connection with
haskell.org you'd have to get the certificate from the DNS, but that
technology is not ready yet, so all you can do is check the key against
as many sources as possible like Michael Walker said.

On Sun, 28 Oct 2012 17:46:06 -0400 Patrick Hurst wrote:
> So why not use HTTPS?

Because it doesn't solve the problem.



More information about the Haskell-Cafe mailing list