3 ms·
I don't think that feasable from a security standpoint. Ideally, software would be open-source and authored under the supervision of a handful of trusted partie
by testific8 5y ago
I don't think that feasable from a security standpoint. Ideally, software would be open-source and authored under the supervision of a handful of trusted parties.
The metaphorical "chain of trust" is strongest when it's composed of a few strong links, and when its cracks are visible.
What you're suggesting is that we should use a model with many small links and invisible cracks.
- kall 5y agoI‘m talking about desktop software for personal computers, not infrastructure software or services or anything. I trust the software developer and I trust apple. There’s a signature/certificate chain between those two. It’s fine. Of course that‘s not acceptable for some people and for some use cases but it is for me.