What is Nostr?
Lennart Poettering /
npub1rk2…zenj
2024-11-04 07:55:01
in reply to nevent1q…2gdz

Lennart Poettering on Nostr: npub1h3vuy…ys7xv sysexts have a much tigther security model than any other forms of ...

npub1h3vuymshqemngzxq4wqeqgcvjcrpqwed5h8rfrck6m84mwdd9sys7ys7xv (npub1h3v…s7xv) sysexts have a much tigther security model than any other forms of packaging/code distribution I am aware of, because of two fundamental features.

1. Signature validation is done by the kernel, hooked into the kernel keyring as a our root of trust, instead of userspace.

2. Contents validation is done via dm-verity, i.e. offline safe on every single block we read.

Both of these concepts are *major* advancement over the status quo ante.
Author Public Key
npub1rk2uxtv6nk262nucavh259t085a8rhzfaj3vjc9jhzvkyav0rnqqxqzenj