• piccolo@sh.itjust.works
    link
    fedilink
    arrow-up
    8
    ·
    edit-2
    20 hours ago

    The point of signing software is to ensure the software was not tampered from the publisher. Linux package managers solve this by comparing a gpg key from the publisher with the software’s. There is no need for a corporate giant to “vet” software.

    • lad@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      I guess, the point was there’s nothing doing that in windows, and you will have to check manually or use an expensive M$ certificate