Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Easy to say. Care explaining? These signatures seem like exactly the thing to prevent mitm attacks. I trust signature A; i won't load the package unless it's signed by signature A.

Most people won't be that strict in informal development, but that's not really what this is about.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: