4 ms·
The analogy to notarizing everything you sign is misguided. Notarization is not required to prove you signed something -- it's usually required to make a legal
by EPWN3D 3y ago
The analogy to notarizing everything you sign is misguided. Notarization is not required to prove you signed something -- it's usually required to make a legal claim about something in the document, e.g. "I am making these claims under penalty of perjury, and this independent party watched me make those claims."
Commit signing provides an integrity and attribution, but that's it. The author seems to think there's some broader meaning to it, but there isn't. Broader meaning can be built on top of commit signing, but that's a separate system that can have a lot of different forms.
I remember reading similar stuff about code signing in the early aughts. The complaints weren't about code signing, they were about accountability. "If I sign this then that means someone can hold me responsible for something that goes wrong." But they can do that anyway -- code signing didn't create a whole new form of tort that was completely impossible before.
There's this sect of software people that seem to think that it's impossible to make legal attributions without the involvement of asymmetric cryptography. Like, they could just show up to court and go "You can't prove that I wrote that software because it's unsigned" and so any legal action against them is impossible. And therefore being forced to sign stuff opens them up to a whole new universe of legal action.
In reality, if someone wants to sue you, they will. If they say that you wrote something, and it looks and smells a lot to a court like something you wrote, the court will determine that you wrote it. So sign your commits -- not because it'll magically make bugs go away, but because supply chain integrity is turning into a real problem really quickly, and this kind of stuff is just table stakes at this point.