gnu-arch-users
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Gnu-arch-users] Re: tla--devo--1.2 has preliminary gpg stuff


From: Miles Bader
Subject: [Gnu-arch-users] Re: tla--devo--1.2 has preliminary gpg stuff
Date: 26 Dec 2003 12:10:21 +0900

Tom Lord <address@hidden> writes:
> Interesting idea.
> 
> The other idea is just to fully generalized so that people can pile-on
> signatures and add attributes to those signatures -- just so we can
> point out that monotone is not that exciting.

Yeah, I just thought of that too; another example might be a tester
that adds his signature to revisions `confirmed via testing'.

> But really I'm pretty skeptical about the robustness and meaning of
> these webs of trust -- I think I'll just stick to a single signature
> for now to meet the immediate needs of project hosts.

I think multiple signature would be very useful without regard to `webs
of trust' -- they just say something about a particular step, and you
might want to later verify that step.  E.g., a mass-mirror operator
might want to verify all his mirrors after a breakin, something which
would be much easier to do without having to have all the original
author public keys, but obviously people that are concerned with the
actual source code might not want to trust the mirror operator.

-Miles
-- 
`The suburb is an obsolete and contradictory form of human settlement'




reply via email to

[Prev in Thread] Current Thread [Next in Thread]