Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Tracking: Security, Trust models, Improving the status quo #2027

Open
3 tasks
kinnison opened this issue Sep 28, 2019 · 2 comments
Open
3 tasks

Tracking: Security, Trust models, Improving the status quo #2027

kinnison opened this issue Sep 28, 2019 · 2 comments
Assignees
Labels
security tracking This is a tracking issue

Comments

@kinnison
Copy link
Contributor

kinnison commented Sep 28, 2019

In order to properly improve rustup's security and trust model, we need to tackle a number of issues. When these are all dealt with, then we'll be in a better position to protect our users and thus we can consider enabling some kind of mirror or alternative-dist-server-by-default mechanisms.

@kinnison kinnison self-assigned this Sep 28, 2019
@kinnison kinnison added the tracking This is a tracking issue label Sep 28, 2019
@kinnison
Copy link
Contributor Author

kinnison commented Dec 5, 2019

So at this time, cargo is out of scope for the work we're doing on the trust model for rustup. Again I ask that you hold off on pushing too hard until after we've opened discussion on the trust model work we're drafting. It'll be a little while, but in the short term I've told you what we have available and if that's insufficient for you then we're unlikely to be able to do anything to satisfy you before we have our proper trust model rolled out. Your point that people who need to use Tor in order to avoid scrutiny or interference from state actors is noted though, and will inform our design process, thank you.

@rust-lang rust-lang deleted a comment Dec 11, 2019
@ms-ati
Copy link

ms-ati commented Dec 12, 2022

@kinnison Hi from Dec 2022! Two years later, wondering if any updates on the trust model for rustup?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security tracking This is a tracking issue
Projects
None yet
Development

No branches or pull requests

3 participants
@ms-ati @kinnison and others