not really, because they would have to exist in the web of trust and be signed by a gentoo developer, a developer could approve the project, and it could be proxied through them until the developer felt they were capable, then they sign there gpg/pgp key, allowing them to bypass the developer who was being the proxy. i think this is a wonderful idea.

On Thu, 2004-01-08 at 04:56, Paul de Vrieze wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thursday 08 January 2004 08:12, John Nilsson wrote:
> > Uh, how silly. Either you trust someone with the whole tree or you
> > don't trust them at all.
>
> Why not build something around a "web of trust" with pgp signatures?
> Have an open tree where people could submit anything that passed
> autotests. All submisions would be signed. Signed content could only
> get updated buy user with same signature or dev with higher trust for
> that area.

This does not help at all for initial submissions. It allows anyone who 
knows how to create a pgp key to get something in the tree. However if 
you make some nuances to this idea, I think it could be workable.

Paul

- -- 
Paul de Vrieze
Gentoo Developer
Mail: [EMAIL PROTECTED]
Homepage: http://www.devrieze.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQE//SlbbKx5DBjWFdsRAmd/AKCrUJtoK0rAh45WfNOBuQQrGjYwhQCgyXnp
8dvq60N2noGeWGygqoG9Rk0=
=sVYb
-----END PGP SIGNATURE-----


--
[EMAIL PROTECTED] mailing list
--------------
Nicholas Hockey ([EMAIL PROTECTED]) Encrypted E-Mail preferred

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to