Elektrine lite

← Feed

@mro@digitalcourage.social

Post #4074199

2026-07-16 11:03 UTC

Hi @eighthave@social.librem.one, being the same as last time and taking responsibility for the product. So individual trust can build over time. Translates to: install (and source tarball, promo material, etc.) is visibly signed by the same dev-generated key.

Replies (1)

  • @eighthave@social.librem.one 2026-07-16 12:02

    @mro@digitalcourage.social I agree, highlighting the role of the signing key seems key. An app signing key is in effect a pseudonym. The hard part is that there is that there is no concrete way for users to verify what the key management practices of the developer are. Judging that from the outside means looking for any signs that the signing key was misused. If a dev wants to hide misuse of their signing key, that is pretty easy to do. For example, they could sign malware and only ship that to targeted users

    Open ##4311845