Replies: 1 comment 1 reply
-
The goal is not to have any single trusted party. Rather, the goal is to provide transparency of the source code being shipped for a web app, and allow this to be checked by any auditor or third party; similar to what Certificate Transparency provides for certificates. |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Could you illustrate your idea showing the benefits of your approach comparing to code signing? The current model is the code publisher signs the webapp by site's SSL certificate (well it could be fouled, but this is another question). So we trust the site publisher. To whom and to what we would trust in your model and how the merkles genuinity will be provided?
Beta Was this translation helpful? Give feedback.
All reactions