Hacker News new | ask | show | jobs
by Jenk 1577 days ago
PGP/SSH is surely the usable here as a 2fa. Have maintainers (or at the least owners) demonstrate their identity with both email and a key.
1 comments

People will lose their GPG/SSH keys. That would cause great havoc with thousands of projects being re-published under new names every year because their authors did not back up his ssh key.

The only proper way to handle that is to ask for national IDs, full names, document numbers. And in case of uncertainty ask photo with those docs and have human support to check it. Of course it should not be required, but just show some kind of "verified" label for those people, that might be enough to push people.

Maybe "ssh keys" alongside those identity documents should become a thing in the digital age.
Estonia includes cryptographic keys with their identity docs, it's like plugging in your passport to be able to prove your identity and sign documents. It sounds like a great system, they only had to re-issue certificates once a few years ago when they realized the keys were too weak, but I can't find any other country that's taken up the decade-old technology.

They also have a state-provided email inbox for official communications, which I wish we had. A friend of mine had her car towed because the registration had lapsed -- she had ignored a letter from the DMV asking for proof of insurance b/c it looked like a scam to her. If only the government had a way to prove ITS identity.