[OLPC Security] Developer Key

Stephen Thorne stephen.thorne at gmail.com
Thu Feb 22 01:16:59 EST 2007


On 2/22/07, Matt Anderson <mra at malloc.org> wrote:
> ... This self-signed key would allow XO
> students to sign applications that they've developed and allow those
> that use these programs to have some degree of certainty as to who's
> programs they are running....

This is an interesting idea for the social aspects of the project, but
I fear that calling it anything that could be confused with the
"Unlock everything and break your XO and let it get stolen and sold on
ebay" "developer key" would be a mistake.

There is a security side to this - being able to have a web of trust
of software authors. It's something that will play a role in the
Develop activity. Andrew Clunis may have some ideas here. I believe
he's planning to use bzr, which has the ability to sign patches.

Develop Resources:
http://wiki.laptop.org/go/Develop
http://orospakr.is-a-geek.org/olpc
http://bazaar-vcs.org/

-- 
Stephen Thorne

"Give me enough bandwidth and a place to sit and I will move the world."
  --Jonathan Lange


More information about the Security mailing list