Comment on Replacement for Docker Content Trust (DCT)

<- View Parent
HelloRoot@lemy.lol ⁨22⁩ ⁨hours⁩ ago

How do you verify that nobody is holding the original developer at gunpoint making them sign their software with their real key?

The point I’m trying to make: At some point, you have to trust something which you can not feasibly verify.

original
Sort:hotnewtop