this post was submitted on 21 Jan 2026
611 points (98.9% liked)

Technology

79061 readers
3144 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] NateNate60@lemmy.world 2 points 21 hours ago (1 children)

I'm guessing what you're suggesting is that Google's proposal is the same as requiring all packages be signed and accompanied by an Extended Validation or Oragnisation Validation X.509 certificate.

While that would technically work, the problem with using the existing PKI is that it's still very expensive to get EV/OV certificates. And the most common of these certs (those for TLS purposes) will soon only last 47 days which is, to put it mildly, would be a pain in the ass to use for package-signing.

[โ€“] x00z@lemmy.world 1 points 18 hours ago

My project uses a free one from SignPath. They offer this for opensource projects and require a verifiable GitHub build process. It's not EV certs but it's good enough and free.