|
|
|
|
|
by exacube
812 days ago
|
|
Is the real identity of Jia Tan known, even by Lasse Collin? I would think a "real identity" should be required by linux distros for all /major/ open source projects/library committers which are included in the distro, so that we can hold folks legally accountable |
|
Google's Know, Prevent, Fix blog post floated the idea of stronger identity for open source in https://security.googleblog.com/2021/02/know-prevent-fix-fra... and there was very significant pushback. We learned a lot from that.
The fundamental problem with stronger identity is that spy agencies can create very convincing ones. How are distros going to detect those?