3 ms·
One of the founders here, this is completely untrue. It's a project funded under the Linux Foundation and the service will be completely run by the Linux Founda
by decodebytes 5y ago
One of the founders here, this is completely untrue. It's a project funded under the Linux Foundation and the service will be completely run by the Linux Foundation, the exact same mode as used for Let's Encrypt.
- kook_throwaway 5y agoThanks for the reply. I'm (hopefully understandably) pretty skeptical of anything google puts their name on nowadays. That said, my speculations were about Google's intentions (not sigstore's) and if you think they are "completely untrue" then you are being misled and should potentially reevaluate the entire project. Banning anonymous and pseudonymous contributors and requiring real names be provided to a trusted party is an explicitly stated goal of Google's[1] and one of the reasons they contribute to the sigstore project in the first place[2]. If I was going to try to make that happen, sigstore is a great way to lay down the infrastructure to implement something like that at a later point. Additionally, anything that will centralize FOSS development (as being a root signing key for software would do) is probably not in it's best interests long term, because at that point the difference between a good and bad actor is a matter of policy and not a technical question. I believe that you have the best of intentions, but others involved in the project clearly don't. [1] https://security.googleblog.com/2021/02/know-prevent-fix-framework-for-shifting.html https://security.googleblog.com/2021/02/know-prevent-fix-fra... [2] https://news.ycombinator.com/item?id=26603661 https://news.ycombinator.com/item?id=26603661
- decodebytes 5y agoPerhaps this this will put you at rest a little. The project was founded in Red Hat along Purdue University (Santiago, part of Arch Linux security team) and Google joined via GOST (The google open source security team). GOST are funded to help improve Open Source Security, they are not there to create products (they are the team that are funding the rust module work in the linux kernel). They were happy to join sigstore as Red Hat were already there first as stewards of it being open source / community centric. I also know Dan Lorenc who heads up the team and he is a great guy and very knowledgable about FOSS and Open Source. If there were any evil intent, I am telling you know, I would be kicking up a storm. Sorry about the "completely untrue" statement, that was not helpful. It's just we face so much unneeded FUD all the time.
- kook_throwaway 5y agoHow does this compare to something like Guix or Nix? It seems those provide many of the same assurances without needing centralized trust.