-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thursday 08 January 2004 08:12, John Nilsson wrote: > > Uh, how silly. Either you trust someone with the whole tree or you > > don't trust them at all. > > Why not build something around a "web of trust" with pgp signatures? > Have an open tree where people could submit anything that passed > autotests. All submisions would be signed. Signed content could only > get updated buy user with same signature or dev with higher trust for > that area.
This does not help at all for initial submissions. It allows anyone who knows how to create a pgp key to get something in the tree. However if you make some nuances to this idea, I think it could be workable. Paul - -- Paul de Vrieze Gentoo Developer Mail: [EMAIL PROTECTED] Homepage: http://www.devrieze.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQE//SlbbKx5DBjWFdsRAmd/AKCrUJtoK0rAh45WfNOBuQQrGjYwhQCgyXnp 8dvq60N2noGeWGygqoG9Rk0= =sVYb -----END PGP SIGNATURE----- -- [EMAIL PROTECTED] mailing list
