Post #4311847
2026-07-16 14:14 UTC
Hi @eighthave@social.librem.one
> users to verify what the key management practices of the developer are
why should they?
> looking for any signs that the signing key was misused
why should they bother? They care if the payload at hand is legit.
> If a dev wants to hide misuse of their signing key, that is pretty easy to do
what attack vector comes to mind?
Replies (1)
-
@eighthave@social.librem.one 2026-07-17 12:39
@mro@digitalcourage.social if the signing key is the root of trust in the developer, then it is important to know that the developer understands that and takes it seriously, and doesn't just give away the keys to the root of trust.