5 ms·
Perhaps I'm sorta nitpicking or being overly annoying by pointing this out, but use of a Yubikey wouldn't necessarily help if a malicious process modified the c
by jka 4y ago
Perhaps I'm sorta nitpicking or being overly annoying by pointing this out, but use of a Yubikey wouldn't necessarily help if a malicious process modified the code to be submitted. They'd be signed-but-corrupted commits.
The best safety net I'm aware of is that source code and/or diffs in plaintext (not binaries) are distributed, and that recipients inspect them.
It's reasonable to distribute binaries in addition, although recipients take on risk by using those. That risk can be mitigated in the presence of source code and reproducible builds.