Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

And if "the proper way to verify committer identity is, as per GitHub's response, a cryptographic signature", Github is certainly not pushing this.

If the only real security around attribution is "a cryptographic signature", GitHub could do a lot better in pushing this, making it essential part of the signup or "getting started" and such.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: