"I have to trust that the interface telling me that he has approved the PR is being truthful when I merge it. " https://github.com/QubesOS/qubes-issues/issues/3958#issue-329274197

They'd love signed OTS'd ACKs:

nostr:nevent1qqsg775h5gza0m0xyxpjf8meysm5yxq54n4xqkhfpn4tn4d6w6rzuucpz3mhxw309akx7cmpd35x7um58g6rsd3e9upzpgqgmmc409hm4xsdd74sf68a2uyf9pwel4g9mfdg8l5244t6x4jdqvzqqqqqqym0p2lk

Reply to this note

Please Login to reply.

Discussion

What's the benefit to using OTS vs PGP signing an ACK that includes the date and time?

Say a vulnerability was merged 1 year ago and it was ACK'd by someone who has since had their PGP compromised. How would you know the ACK was signed ahead of the merge rather than after the key compromise?

Its also a lot more convienent to sign and verify messages as every interaction has to be signed.

Good point.