PSA: Please sign your git commits



Summary:

The context discusses the concept of multisig, which is beneficial for irreversible actions but not necessary most of the time. Although it has been implemented in bitcoin wallets, no PGP developer or user ever thought to implement it. The compromised process of PGP keyring is rarely exercised and lacks 2FA. Wladimir suggests that multisig could be useful for git commits to reduce damage when a developer's computer is compromised, but admits that it would require a lot of work to establish a good workflow. He concludes by encouraging others to pick up the idea if interested.


Updated on: 2023-06-08T23:13:56.387712+00:00