Hacker News new | ask | show | jobs
by avgcorrection 842 days ago
Completely correct that you should have a reason for signing something which goes beyond the vacuous “why not”.

In my own work, the surrounding context is sufficient verification.

By the way: patch attestation [1] is perhaps somewhat related. Pretty well-thought out techniques for verifying that patches sent via email.

[1] https://lwn.net/Articles/813646/