First: You don't have to sign your code. Second: We rely on "centralization" for TLS as well. Third: Third-party verification can be done within the community itself ( .


I don't disagree. But what is wrong with the notion of introducing an
_additional_ layer of certification?
Adding an additional layer of centralization.

