From: Dan Sugalski Date: 2002-01-08T00:15:11+09:00 Subject: Re: snippet exchange (was: Re: Re: chomp for arrays?) At 03:39 PM 1/7/2002 +0900, Holden Glova wrote: >On Mon, 07 Jan 2002 16:39, Rich Kilmer wrote: > > I did not say anything about a remote keyserver. I said to have a Gem(Jar) > > cryptographically signed through the process of generating a public/private > > key pair (as a library developer) and then generating a SHA hash of the Gem > > and encrypting the SHA with the private key. You then upload the Gem with > > the SHA/public key as a bundle to validate that it was in fact not changed > > and from the public keys owner. Now, the method by which I download the > > public keys of developers I "trust" is definately an issue but there are > > emerging systems that are being developed to [help] solve this problem in a > > distributed (rather than centralized) fashion that fall under the name > > "reputation networks". > >I believe this is how Loki (http://www.lokigames.com - games for the penguin) >release any patches to their released games. They and Blizzard both distribute patches via the net, but they're signed and the client has the key to start with. Dan --------------------------------------"it's like this"------------------- Dan Sugalski even samurai dan@sidhe.org have teddy bears and even teddy bears get drunk