Marija_@lemmy.ziptoTechnology@lemmy.world•OpenAI admits responsibility for HuggingFace Attack - an agent from an internal evaluation is reportedly the causeEnglish
5·
1 day agoThat incident raises serious supply-chain questions.
That incident raises serious supply-chain questions.
Software supply chains already rely on digital signatures. That’s fine, but the problem is that they’re often controlled by teams rather than individuals, making malicious or unauthorized changes much harder to trace. It’s much better for the public key to function like a vehicle license plate, verifiable without revealing the person’s identity unless there’s been a problem. That preserves privacy while introducing accountability. The kind of projects like Osmio are trying to achieve.