Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Sigh.. This could be somewhat repaired by making a beta-release, distributing to devs and testers. Once confirmed good, rename file and release via IPFS. The key here, is if multiple devs did this, the hashsum would prove the file being shared.

Any one client that's been hacked or infected would show up as an improper hash and easily spotted.



hindsight is always 20/20

i'm sure <insert your favourite open source project here> would appreciate patches for reproducible, cryptographically signed releases




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: