• nintendiator@feddit.cl
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 year ago

    Because you need a way to be reachable over HTTPS

    Feels like this is the core key to be changed. Something like Debian’s packaging system for example, which doesn’t even need the Debian domain to be HTTPS.

      • nintendiator@feddit.cl
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        1 year ago

        Dunno the exacts, but why not the good ol’ GPG? You only need to be able to exchange keys out-of-band once, and it saves you from lots of other issues. Trust between Alice and Brian is a between-them thing, and should not depend on a thrid party like Caroline arbitrarily deciding to change Brian’s legal name to Brandon.

    • Max-P@lemmy.max-p.me
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      Debian packages are signed individually, and usually people also don’t see downloading Debian packages as potentially privacy-sensitive, so plain download is acceptable.

      For lemmy where user accounts are involved, and in general as a new protocol designed in the age of HTTPS, it makes sense to require HTTPS.