Conversation

Replying to and
I don't know what else to say beyond that I didn't say that. I don't understand why you're mad at me. I've been trying my best to clarify what I said initially and I wasn't trying to turn it into something hostile.
1
Replying to and
I don't know what negged means in this context. I was trying to present 2 counterexamples to package signing done via centralized servers. Until recently, all Android apps were signed with developer keys (vast majority still are) and there are distributions not centralizing it.
2
Part of my point was that these are imperfect systems without fancy things like reproducible builds + multisig, but yet they're still very useful and a lot better than the alternative of not having package signing. Even just having TOFU via the lock files would be quite useful.
1
I was curious about what exactly the old developer had to do in order to hand off control and was surprised by there not being a mechanism for even doing TOFU pinning. I thought they'd have had to hand over a key, but it's mostly just a username/password protecting each package.
1