logoalt Hacker News

mschwaiglast Saturday at 2:28 PM0 repliesview on HN

I wrote a paper about how I think trust should work for software dependencies.

It very much builds on the hash-based cache lookup mechanism this paper calls constructive traces (in contrast to what they call deep constructive traces) to eliminate transitive trust relationships.

https://dl.acm.org/doi/10.1145/3689944.3696169