X-Recipient: archive-cygwin AT delorie DOT com DomainKey-Signature: a=rsa-sha1; c=nofws; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:date:from:reply-to:to:message-id:subject :mime-version:content-type:content-transfer-encoding:references; q=dns; s=default; b=S/fjpQsJO2YdtsqyLipEP28Ii0pkhXryYM833tc5omV /4k72+vUTjC31aG9cEK1TaOUnicrAqewG/yzKjM6kk06ECdRBcOvRiWSru+5GJtO s+1RXm4O4uWbV/rzlwyOczhIpHsiaw4KuvGF7xUF1Gu5tTr2RBHsIc1kK8Z2xfI0 = DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=sourceware.org; h=list-id :list-unsubscribe:list-subscribe:list-archive:list-post :list-help:sender:date:from:reply-to:to:message-id:subject :mime-version:content-type:content-transfer-encoding:references; s=default; bh=6g1dWGKH3t4NREudunVT/MJG2lQ=; b=sVsWPG7mHyp7+mQKE ajyyriSlAELBj5ARjH5jLAD8CdTzjGy34idujZoAxAPZNLI6S+mnqDLKx/dPeU8j FSIqhNCNtU7O8n4UkzNmEA0/aNUDXBgQw13Yv6Cnuf66/sJddzdIZ6XhqDWuhGae ksw04j9ZjjCyqywBIpReaQCflw= Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm List-Id: List-Subscribe: List-Archive: List-Post: List-Help: , Sender: cygwin-owner AT cygwin DOT com Mail-Followup-To: cygwin AT cygwin DOT com Delivered-To: mailing list cygwin AT cygwin DOT com Authentication-Results: sourceware.org; auth=none X-Virus-Found: No X-Spam-SWARE-Status: No, score=1.9 required=5.0 tests=AWL,BAYES_60,FREEMAIL_FROM,KAM_COUK,RCVD_IN_DNSWL_LOW,SPF_PASS autolearn=no version=3.3.2 spammy=H*R:D*uk, H*R:D*co.uk, H*RU:sk:tm1.bul, Hx-spam-relays-external:sk:tm1.bul X-HELO: nm30-vm6.bullet.mail.ir2.yahoo.com Date: Wed, 17 Aug 2016 01:49:59 +0000 (UTC) From: Reply-To: To: "cygwin AT cygwin DOT com" Message-ID: <1740128398.25713364.1471398599819.JavaMail.yahoo@mail.yahoo.com> Subject: Cygwin's installation and security models? MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit References: <1740128398 DOT 25713364 DOT 1471398599819 DOT JavaMail DOT yahoo DOT ref AT mail DOT yahoo DOT com> I'd like to understand Cygwin's installation and security models better: - Cygwin's installers aren't signed. - downloads are from a number of untrusted mirrors via http/ftp, and packages aren't verified. Is this correct? thanks Lloyd Wood lloyd DOT wood AT yahoo DOT co DOT uk http://savi.sf.net/ -- Problem reports: http://cygwin.com/problems.html FAQ: http://cygwin.com/faq/ Documentation: http://cygwin.com/docs.html Unsubscribe info: http://cygwin.com/ml/#unsubscribe-simple