Hacker News new | ask | show | jobs
by brl 4339 days ago
Yawn. Let me know when you're ready to announce a project to competently sign and verify artifacts.
2 comments

Signatures have been required on Central for years and there are tools to verify them, including repository managers.

We strongly do not believe that you should entrust your private key to anyone else for signing, which is what others have done to make it easy....yet less secure.

Maybe you could assist them?