> Is it really that hard to check a digital signature? I wouldn't think so, but the fact is that we haven't implemented it yet, and we're in all sorts of freezes by now.
Also, there's the people-security issues of who has access (or how do they get access) to the keys (and is that access revokable, and what happens if somebody crucial gets hit by a bus), and what the final master list URL is (which, as Shaun correctly mentions is part of the API, just like the new D-Bus interface org.gnome.NewStuffManager), how is this list hosted, and how is it updated. There's just a lot of work to get from proof-of-concept code to slapping "stable" and "(not obviously in)secure" stickers on it, IMHO. _______________________________________________ desktop-devel-list mailing list [email protected] http://mail.gnome.org/mailman/listinfo/desktop-devel-list
