Modern Software Registries Are a Trust Service

(redmonk.com)

1 points | by mooreds 9 hours ago ago

1 comments

  • ggm 9 hours ago ago

    There are many paths out from this observation. My principal fear is the ones taken will favour capture by authority models which are not community led, but are impositions of "we badge this acceptable" from above.

    Badging as acceptable and true might need to be done, its about whose hands are on the tiller.

    The ICANN/IANA KSK is an example of a unitary authority signing important things, using slightly melodromatic witnessed HSM keying ceremonies, to ensure some level of exposure of things done at an apex.

    I'd rather have that, and it's costs, than have this embedded in the EU complex in brussels behind mandarins, or working under the control of the department of state in the USA -noting that the KSK is unfortunately landlocked to the USA and lies behind USA TSA/CBP/ICE access by the witnesses into the facilities since we don't have a tunnel to get there magically without crossing border controls or the US jurisdictional limit.

    Secure boot entry rights are in the same kind of space. It's a dilemma.

    I'd like (for instance) the NPM registry to have a well known trust anchor I can point to, so I understand things to be blessed by them, using a CDN to access the contents. Admission controls to their dependency chain and package flows through their checks, and is gated in their TA. Unblessing should be possible, so that malware can be ejected.