X-Spam-Check-By: sourceware.org Date: Fri, 11 May 2007 21:47:20 -0400 From: Christopher Faylor To: cygwin AT cygwin DOT com Subject: Re: MD5s of setup.exe on mirrors. Message-ID: <20070512014720.GB30086@ednor.casa.cgf.cx> Reply-To: cygwin AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com References: <5qd5179mvu DOT fsf AT hod DOT lan DOT m-e-leypold DOT de> <4644CB03 DOT 9070707 AT determina DOT com> <20070511202353 DOT GA25421 AT trixie DOT casa DOT cgf DOT cx> <4644E349 DOT 7000604 AT determina DOT com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <4644E349.7000604@determina.com> User-Agent: Mutt/1.5.14 (2007-02-12) Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm Precedence: bulk List-Id: List-Unsubscribe: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com On Fri, May 11, 2007 at 02:42:33PM -0700, Alexander Sotirov wrote: >Christopher Faylor wrote: >>>Nobody seemed to care. Considering the fact that MD5 collisions are >>>now trivial to generate, it probably doesn't matter much anyways - the >>>fact that your copy of setup.exe has the right MD5 doesn't mean that it >>>hasn't been tampered with. >> >>We don't control the content of mirrors. >> >>If you think this is an issue, contact the mirror(s) in question. > >This is an issue with the Cygwin website, not the mirrors. That is your opinion. >There is a chain of trust from http://cygwin.com to the mirrors. Since >the official Cygwin site list these mirrors at >http://cygwin.com/mirrors.html, you're endorsing them as an officially >approved locations to download Cygwin. This means that you have to >monitor reports about misbehaving mirrors and remove ones that >distribute corrupted or possibly malicious binaries under the Cygwin >name. If/when we find a mirror distributing a malicious binary we will remove it. However, in the meantime, I would suggest that people only use the setup.exe that is distributed from cygwin.com, i.e., click on the "Install Cygwin Now" link. -- Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple Problem reports: http://cygwin.com/problems.html Documentation: http://cygwin.com/docs.html FAQ: http://cygwin.com/faq/