|
|
|
|
|
by lukeschlather
4081 days ago
|
|
> That's kind of a shame. It would be nice if apps distributed over the web could be signed the same way they are from repositories. This sounds like a theoretical impossibility. The server's source code is by nature closed, and while the server could provide you a copy of the source with a signature, there's really no way for you to verify that the code you've been promised is the code that is running. |
|
I don't see how it's a theoretical impossibility.