Marcus Rohrmoser 🌻
Rents out liberated laptops 🐧 🌿 https://mro.name/laptop
Built the social web 🚲 https://Seppo.mro.name with 🐫 @ocaml@mastodon.social. Incubated by https://NLnet.nl/project/Seppo.
Continues to make things deemed impossible.
Occasional (lightning) talker https://mro.name/talks. Former ☕ JEE and 📱 iOS developer, past 🌳 tree planter. Netizen since the mid 90ies.
Member of https://SIGCHI.org, https://CCC.de, https://FIfF.de, https://GI.de, https://NOYB.eu, https://Blaetter.de, https://ADFC.de.
Likes 😈 https://mro.name/FreeBSD-XFCE 🐁 and 🏔️ @alpinelinux@fosstodon.org.
Hi @captainfutura@mastodon.social
dass man die Menschen, die man regiert, vielleicht auch irgendwie mögen sollte.
Hi @eighthave@social.librem.one
users to verify what the key management practices of the developer are why should they?
looking for any signs that the signing key was misused why should they bother? They care if the payload at hand is legit.
If a dev wants to hide misuse of their signing key, that is pretty easy to do what attack vector comes to mind?

