Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't disagree. The current state of git signing is pretty bad. I wrote more here: https://link.medium.com/zqy8VVzAJqb

I'm a maintainer on gitsign and think we can fix it though!



Thanks for pushing the state of the art on this. Personally I'm not a fan of git signatures either because they seem to pair something supposed to be permanent (a commit) to something supposed to be ephemeral (a signing key). (Distributed) ledger technology can absolutely improve the status quo here.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: