Message boards : Cafe Rosetta : Code signing procedures
Author | Message |
---|---|
brunni Send message Joined: 3 Mar 20 Posts: 2 Credit: 0 RAC: 0 |
From https://boinc.berkeley.edu/wiki/BOINC_Security So, if you're concerned about security (and you should be!) don't attach to a project unless it can convince you that it follows the code-signing procedure correctly. Ask project administrators to describe how they do code signing. So here I am, asking about your code signing procedures. |
Mod.Sense Volunteer moderator Send message Joined: 22 Aug 06 Posts: 4018 Credit: 0 RAC: 0 |
The project does use code signatures. The BOINC Manager then verifies each download against the signature to assure nothing has been modified or corrupted during the file transfer. But I'll check with David Kim and see if there is something more specific he can provide. Rosetta Moderator: Mod.Sense |
Admin Project administrator Send message Joined: 1 Jul 05 Posts: 4805 Credit: 0 RAC: 0 |
We do follow the guidelines. |
brunni Send message Joined: 3 Mar 20 Posts: 2 Credit: 0 RAC: 0 |
We do follow the guidelines. So the code-signing keys are not on a network-connected computer? |
Message boards :
Cafe Rosetta :
Code signing procedures
©2024 University of Washington
https://www.bakerlab.org