From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: Changing guix download page from using HTTP to HTTPS Date: Sun, 5 Mar 2017 13:36:15 -0500 Message-ID: <20170305183615.GA12515@jasmine> References: <87shmr7o1e.fsf@gmail.com> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="fUYQa+Pmc3FrFX/N" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:51371) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ckb15-0001NI-3d for guix-devel@gnu.org; Sun, 05 Mar 2017 13:36:24 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ckb10-0005Wc-6r for guix-devel@gnu.org; Sun, 05 Mar 2017 13:36:23 -0500 Received: from out4-smtp.messagingengine.com ([66.111.4.28]:40845) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1ckb10-0005WY-35 for guix-devel@gnu.org; Sun, 05 Mar 2017 13:36:18 -0500 Content-Disposition: inline In-Reply-To: <87shmr7o1e.fsf@gmail.com> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Alex Vong Cc: guix-devel@gnu.org --fUYQa+Pmc3FrFX/N Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sun, Mar 05, 2017 at 11:15:25PM +0800, Alex Vong wrote: > Hello, >=20 > In the guix download page[0], it mentions "Source code for the Guix > System Distribution USB installation images as well as GNU Guix can be > found on the GNU ftp server for alpha releases: > http://alpha.gnu.org/gnu/guix/ (via HTTP) and > ftp://alpha.gnu.org/gnu/guix/ (via FTP).". >=20 > Should we change "http://alpha.gnu.org/gnu/guix/ (via HTTP)" to > "https://alpha.gnu.org/gnu/guix/ (via HTTPS)"? Absolutely. Everyone *should* verify the signatures, but I know that many people do not. HTTPS makes it harder to perform a man-in-the-middle attack on those users, and it also gives them some privacy. --fUYQa+Pmc3FrFX/N Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAli8WpwACgkQJkb6MLrK fwgCTRAApBDrrPof7DY5vrizCiicWpLCvuryahGPDm7A8KpynOhWx+dzVDfIcl/Z Ipnqak9ryfTvKxZM2VQdEdX3rg5u3fZlJ5NUWkrS6akJJzZamu7Lz3tzeBQhmutR B90I+iY3CSCw2VFvETPrPWUFuZdyVCs0udHV5zZiwQ7fVbrEojouWwldJf9PpOxH YuVIjoCSij7vq4yestppoo2h0YB1EoJFLwbXSqqWm2w9ELo+xISNk1EXDtIiDbR9 iFYoF2ArDRd/0JGhCppb66LtMugLxySz8lGRoI7BXPGRV9NIQ9HV11xQL49n98of XI/3utYV2vred110CXC9/nEYCuCC0oy28TvBm0+zC0wpSU9sPJ2v6aMVvV+7AUyG Bs4Hy1LNl91lY8w5lAysMYloKwzFaCpqpFMUB703bQijYX9g7jamOSklFM+XoEwh cpb9MMdWF+n1hsH4l8TNfhpy2yYJd9otwi4jK7yycWqxi+95e60qLUx1X35tqzmt GCz7PKdIAla9N9HJVSWdHDNQTqwxqZfhA0K2Oyfo9mcc0sTpdtNKjIu2bWowqlq/ H1xScuTkoM6Gz3FwUg6E9NjVgam7NmQyrOlEP0LklHdP2v7q/BjkRwsZKEUyrdkT OmXIpqURc9dkphLhTNCipUWtZzgPzYkEvdAdu1hHJ2uksPAzJvI= =Z93/ -----END PGP SIGNATURE----- --fUYQa+Pmc3FrFX/N--