How does this works then?
Because you need a way to be reachable over HTTPS
Feels like this is the core key to be changed. Something like Debian’s packaging system for example, which doesn’t even need the Debian domain to be HTTPS.
kratoz29@lemmy.world 1 year ago
nintendiator@feddit.cl 1 year ago
Dunno the exacts, but why not the good ol’ GPG? You only need to be able to exchange keys out-of-band once, and it saves you from lots of other issues. Trust between Alice and Brian is a between-them thing, and should not depend on a thrid party like Caroline arbitrarily deciding to change Brian’s legal name to Brandon.
themoonisacheese@sh.itjust.works 1 year ago
They don’t need it per se but there’s a reason apt-transport-https is a very popular package.