Hacker News new | ask | show | jobs
by joshka 998 days ago
Signed locally using your GPG key is the correct answer to this (IMO), otherwise you're replacing a one attestation with a much weaker one.