Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't think that works.

Attackers could generate a key and sign a hacked artifact. Yes, somebody signed that artifact you might say, but I would worry who signed it and how much I should trust them.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: