On Wed, Sep 26, 2001 at 09:38:40PM +0200, Johan Wevers wrote:

> David Shaw wrote:
> > While it is true that virii often try to masquerade as harmless
> > attachments, nevertheless a signature is not a binary or executable
> > code of any sort.
> Neither is a patch on source code, but a malacious patch can intruduce
> a security weakness in a program, even when it's not obvioud to the
> casual observer (I don't expect anyone to send out source patches with
> code that explicitly mails a secret key to the attacker, but subtle
> flaws might be introduced unnoticed).
Yes, which is why such things should be signed by the developer.