this post was submitted on 12 Jul 2026
15 points (67.4% liked)
Linux
14831 readers
1078 users here now
A community for everything relating to the GNU/Linux operating system (except the memes!)
Also, check out:
Original icon base courtesy of lewing@isc.tamu.edu and The GIMP
founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I'm getting AI slop and security theatre vibes. The cross-signed keys is especially pointless when both are owned by the same person physically. No one will steal just one, they'll steal both.
And its impossible for an end user to verify that the packages are actually clean, there is way too much surface area for a compromised package to be slipped in.