-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thursday 08 January 2004 08:12, John Nilsson wrote:
> > Uh, how silly. Either you trust someone with the whole tree or you
> > don't trust them at all.
>
> Why not build something around a "web of trust" with pgp signatures?
> Have an open tree where people could submit anything that passed
> autotests. All submisions would be signed. Signed content could only
> get updated buy user with same signature or dev with higher trust for
> that area.

This does not help at all for initial submissions. It allows anyone who 
knows how to create a pgp key to get something in the tree. However if 
you make some nuances to this idea, I think it could be workable.

Paul

- -- 
Paul de Vrieze
Gentoo Developer
Mail: [EMAIL PROTECTED]
Homepage: http://www.devrieze.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQE//SlbbKx5DBjWFdsRAmd/AKCrUJtoK0rAh45WfNOBuQQrGjYwhQCgyXnp
8dvq60N2noGeWGygqoG9Rk0=
=sVYb
-----END PGP SIGNATURE-----


--
[EMAIL PROTECTED] mailing list

Reply via email to