5 ms·
Perhaps we need a letsencrypt for signing packages on walled-garden systems.
by goodplay 9y ago
Perhaps we need a letsencrypt for signing packages on walled-garden systems.
- tonyedgecombe 9y agoCode signing requires some verification that you are who you say you are in the real world so there is an additional cost.
- goodplay 9y agoNot necessarily. For issues like the one discussed in this thread, a simple ssh-style "trust initially" would have sufficed, and would have prevented the malicious installer from running. Note that I'm not proposing this as a replacement for the current cert system (which you pay into), but as a replacement for unsigned executables.