3 ms·
Seems to me stronger user accounts could be bolted onto an existing DVCS quite easily. The hard part would be working out the PKI, but adding digital signatures
by cmars232 16y ago
Seems to me stronger user accounts could be bolted onto an existing DVCS quite easily. The hard part would be working out the PKI, but adding digital signatures to commit objects would be easy.
PKI probably would need to be pluggable to meet the variety of project needs out there. I'd imagine enterprise projects would use a corporate CA, some small startups or open source might be comfortable with a quick-start "ring-of-trust" distributed scheme, etc. Github and other hosting providers could offer CA services. Interesting way to prove code ownership in any case.
- masklinn 16y agoI think "bolted on" would precisely be the issue. That tends to translate into "bypassable" and "brittle".
- gecko 16y agoThis is actually one of the two things about this product I find most interesting. Having a user-friendly public key system is really tough to get right, even when you're targeting programmers. Look at Monotone, for example: I'd argue they've basically got it right now, but it took them a long time to come up with sane ways for handling things like a user losing their keyring. Veracity will have to get this right from the get-go if they want to nail the enterprise market.