4 ms·
> software update cryptography is both a solved problem (just use signify) Well, just use TUF [1] and in-toto [2] ;) [1] https://theupdateframework.io/ https:
by trishankdatadog 6y ago
> software update cryptography is both a solved problem (just use signify)
Well, just use TUF [1] and in-toto [2] ;)
[1] https://theupdateframework.io/ https://theupdateframework.io/
[2] https://in-toto.io/ https://in-toto.io/
- theamk 6y agoNote that TUF is great for things with multiple contributiors (think npm or pypa). For the simple case of "a single publisher publishes update for a single product", TUF is an overkill. Something like signify or seccure will be way easier to set up and use.
- trishankdatadog 6y agosignify is nice when key distribution, revocation, and rotation is handled for you... but how do you do that securely for many different publishers on a single repo?