3 ms·
Isn't this what part of the point of cryptographically signed artifacts such as via GPG is for anyway? Historically Linux package managers explicitly avoided us
by devonkim 3y ago
Isn't this what part of the point of cryptographically signed artifacts such as via GPG is for anyway? Historically Linux package managers explicitly avoided using TLS / SSL for distributing binaries over networks because they wanted the userbase to build a habit of verifying signatures and checksums provided by the distro maintainers at every step of the process as part of the shared responsibility model.