Comment by gruez
5 hours ago
PGP keys don't tell you anything about a developers "real identity". Theoretically theres some "web of trust", but realistically everyone just blindly downloads whatever PGP key is listed on the repo's install instructions.
No comments yet
Contribute on Hacker News ↗