|
|
Subscribe / Log in / New account

Verify the identity of developers

Verify the identity of developers

Posted Apr 4, 2024 18:59 UTC (Thu) by epa (subscriber, #39769)
In reply to: Verify the identity of developers by kleptog
Parent article: A backdoor in xz

If the developer’s public key is signed by a government agency and linked to their identity document (as apparently can be done in Germany) that is a stronger check than just checking a passport and associating it with a public key uploaded separately.

None of this is completely watertight. But right now it’s kind of embarrassing how easy it is to create a fake identity and use it to contribute or even become maintainer of a project.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds