|
|
|
|
|
by rsc
812 days ago
|
|
Open source fundamentally does not work that way. There are many important open source contributors who work pseudonymously. Google's Know, Prevent, Fix blog post floated the idea of stronger identity for open source in https://security.googleblog.com/2021/02/know-prevent-fix-fra... and there was very significant pushback. We learned a lot from that. The fundamental problem with stronger identity is that spy agencies can create very convincing ones. How are distros going to detect those? |
|
I realize, it's a hard problem. (And, thanks for the link to the "Know, Prevent, Fix" post.)
PS: FWIW, I "win my bread" by working for a company that "does" open source.
Edit: Some projects I know use in-person GPG key signing, or maintainer summits (Linux kernel), etc. None of them are perfect, but raises the bar for motivated anonymous contributors with malicious intent, wanting to become maintainers.