Hacker News new | ask | show | jobs
by tfvghbv 3256 days ago
> the trust path for a huge chunk of binary data now hinges on a single individual, rather than a corporate entity.

You make it sound like it was a bad thing. It's not.

3 comments

It is definitely a bad thing from a risk standpoint, no two ways about it. Simply because that person could get hit by a bus, burn out, etc.
I'd trust Canonical for Ubuntu images over a random internet citizen that decided to provide them.
When it comes to base images, I'd much rather trust Canonical, Docker Inc, Redhat, etc than Some Dude.