Comment on What is Docker?

<- View Parent
jagged_circle@feddit.nl ⁨1⁩ ⁨week⁩ ago

PKI.

Apt and most release signing has a root of trust shipped with the OS and the PGP keys are cross signed on keyservers (web of trust).

DCT is just TOFU. They disable it because it gives a false sense of security. Docket is just not safe.

source
Sort:hotnewtop