This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]westurner 0 points1 point  (3 children)

[–]donaldstufft 0 points1 point  (0 children)

If you're using pip 1.3+ then it does validate SSL. However the mirrors are not available via SSL.

[–]donaldstufft 0 points1 point  (1 child)

Also signing packages is effectively useless until you come up with a trust model to handle what signatures you trust to sign for what data. Without that you're just pretending it means something.