Hacker News new | ask | show | jobs
by sneak 1003 days ago
Docker content trust (ie signature checking) is disabled by default.

We won't even do this for webpages, but we find it a fine default for code that executes inside critical infrastructure.

It's utter madness. Cool to see someone is doing something about it.