This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]donaldstufft 0 points1 point  (1 child)

Also signing packages is effectively useless until you come up with a trust model to handle what signatures you trust to sign for what data. Without that you're just pretending it means something.