Hacker News new | ask | show | jobs
by allegory 4325 days ago
Ship the public key by post like internet banking in the early 2000s.

This is actually how OpenBSD operates. If you buy an official CD set, the thing ships with keys which are then used to sign downloaded packages.

When the keys go via a side channel, the probability of compromise decreases considerably.