Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Who signs an "app" when I download it from Homebrew?

If all Homebrew "apps" are the same key then accepting a keyring notification on one app is a lost cause at it would allows things vulnerable to RCE to read/write everything?





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: