Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> the trust path for a huge chunk of binary data now hinges on a single individual, rather than a corporate entity.

You make it sound like it was a bad thing. It's not.



It is definitely a bad thing from a risk standpoint, no two ways about it. Simply because that person could get hit by a bus, burn out, etc.


I'd trust Canonical for Ubuntu images over a random internet citizen that decided to provide them.


When it comes to base images, I'd much rather trust Canonical, Docker Inc, Redhat, etc than Some Dude.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: