|
|
|
|
|
by marksomnian
11 days ago
|
|
That's exactly where I keep getting caught. I've looked at in-toto a number of times, and each time I've been left wondering "how is this better than a signed list of hashes?". Which I suppose is what in-toto is at its core, but it's taken me a long time and lots of reading to get to that point, and I'm not seeing the advantages of it (except it being a standard, OK, fair enough). I must be missing something. |
|
1. I guess this depend on your position. In the context of remote attestation, I think this is also even dangerous / evil.