• StarDreamer@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      22 hours ago
      1. If your assumption is that X509 is trash, does that mean you hold the same amount of distrust to TLS?
      2. How do you propose the scaling of key management? Do you have a reasonable alternative to users blindly trusting every single key they come across?
      3. Back to my original question: what prevents a VSCode extension from stealing a private signing key (as opposed to an API key) and causing the same issues described here?