3 ms·
> That's why you have to trust the author and NOT the source. The author is the first creator of the code and thus the person with the most ability to sign the
by donaldstufft 13y ago
> That's why you have to trust the author and NOT the source. The author is the first creator of the code and thus the person with the most ability to sign the code.
Source of Trust, not Source of The Thing You Downloaded. The author would still sign the package, it's just how do you get from where you're at to trusting that person. The way that browsers, most (All?) Linux distributions, Microsoft etc work is by hard baking a list of trust roots. This has the effect that we have in the modern CA system where because there's a hard baked system and the trust relationship is between the "author" and the source of trust that you can't reasonably not trust say Verisign or a significant portion of the internet breaks. It's about Trust Agility not about trusting the place you downloaded the package from. It's an idea similar to http://convergence.io/ http://convergence.io/.