Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They don't really do any source authentication at all. There is no strategy for checking gpg/minisign/whatever signatures and fetching keys to validate these things.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: