3 ms·
You're pretty much spot on. The problem is less about signing and more about existing PKI for git commit signing. We're working with David Huseby to help refact
by dlor 5y ago
You're pretty much spot on. The problem is less about signing and more about existing PKI for git commit signing. We're working with David Huseby to help refactor the way gpg is coupled with git to enable stronger/different PKIs: https://github.com/TrustFrame/git-cryptography-protocol https://github.com/TrustFrame/git-cryptography-protocol
I always personally struggle to recommend signing when it's so hard to do correctly. Until there's actually something workable, that supports time-stamping like you mentioned it seems like a false sense of security at best.
- er4hn 5y agoThanks for sharing this. This is very interesting and I did not know about it. I'll make a note to read it and see if there are any useful contributions I can make.