4 ms·
So? Who says the verified package isn't malicious? My point isn't about cryptography, it's about complexity. Unless you personally read through every line of co
by mcantor 14y ago
So? Who says the verified package isn't malicious? My point isn't about cryptography, it's about complexity. Unless you personally read through every line of code, how do you really know that there isn't something in there waiting to screw you over?
- aw3c2 14y agoI trust my system's package maintainers and the signing makes sure that it is them. I do not trust a random website that could easily be MITMd.
- VMG 14y agoSo you'd be fine with https?
- brohee 14y agoYou don't know. What you know however is who to sue if the package ends up being malicious, thanks to the signature.