Conversation

Replying to and
Most Linux distributions fully trust the packagers and a central build / signing server, along with not verifying signatures for sources. I think you're unfamiliar with how it works elsewhere if you think trusting 20 vetted people to sign builds of packages is bad.
2
Replying to and
You're linking in a thread where you've previously made comments like twitter.com/bascule/status. I feel like you've been trying to ridicule everything I've said and I don't understand why.
Quote Tweet
Replying to @bascule @DanielMicay and @hdevalence
...and sure, it works great if you don’t give a fuck about the practical implications ¯\_(ツ)_/¯
1
Replying to and
I made 2 initial comments about the topic (twitter.com/DanielMicay/st) and tacked on one more after I looked into npm and noticed it had no package signing. I didn't intend for that to be directly related to the main issue. I just found it surprisingly they have no package signing.
Quote Tweet
Replying to @hdevalence and @bascule
If they wanted him to have the responsibility of doing due diligence, companies depending on his library should have paid him. He stated that he was doing it for fun and it stopped being fun so he handed it off to someone else as quickly as they showed up. It was a hobby project.
1
I was wondering what they had do to hand over control to a different developer. It seems pretty bad if the security of the ecosystem depends on the strength of passwords chosen by people uploading to the site. Then it became an argument about whether package signing is feasible.
1
Replying to and
You were the one wandering off on these many tangents, and making the conversation incredibly difficult to follow, failing to clarify what I got wrong. And all this while pushing a solution I do not consider to be insecure, while belittling me about failing to understand.
1
1
Replying to and
I was replying to your comments and arguing that package signing is completely feasible and can be done with varying tiers of security that are still useful despite lacking perfection. I was frustrated by having my thoughts on that ridiculed / dismissed as clueless.
1
Replying to and
You are describing a system I do not consider to be secure, and that I would not use, and at the same time being a pompous blowhard about it and wondering why everyone thinks it's such a hard problem when you have failed to solve it. I am done with this conversation.
1