Add sig-prover

Sig-prover is a tool I use to random-check mirrors for signs of tarball
corruption (or worse). It will download random kernel/git/etc tarballs
fron the frontends and verify them against the signatures, alerting when
there is a verification failure.

This script is not a guaranteed mechanism to detect intrusion -- an
attacker can defeat it by analyzing access patterns/IPs and serving
different content when it suspects that someone is running an automated
signature verification check. The script can probably be improved by
adding random delays between retrieving the tarball and the detached
signature, setting a referrer value, etc. However, even with added
measures, it will always act fairly predictably, so there will always
remain a way to defeat it.

Signed-off-by: Konstantin Ryabitsev <konstantin@linuxfoundation.org>
6 files changed