|
|
|
|
|
by lrvick
73 days ago
|
|
What they need to mandate is hardware anchored passkeys/fido2/webauthn for both auth and package signing, with the -option- to sign with PGP for those that have well trusted PGP keys. They won't do this, I have talked to them plenty of times about it. But, if they did, the supply chain attacks would almost entirely stop. |
|