development platform, and often also on production servers. • We tend to do this with a privileged (root) account. • We don’t and cannot verify the integrity of this process.
time: signing. • We take trust in a certificate or key. • Everything that is signed with that certificate / key, is automatically trusted. • “web of trust” • apt-get install, yum install
They won't succeed. You need to know exactly 20 bytes, you need to know 160-bit SHA-1 name of the top of your tree, and if you know that, you can trust your tree, all the way down, the whole history. You can have 10 years of history, you can have 100,000 files, you can have millions of revisions, and you can trust every single piece of it. .... http://www.youtube.com/watch?v=4XpnKHJAok8 Google TechTalk: Linus on Git
effectively been eliminated in the sysadmin world after decades. • They are insecure and relinquish control to other non-trusted parties. • We should not allow PHP developers to embrace the worst practices.
tools that use this to implementing correct signing mechanism. • It’s possible. We can sign composer, and we can sign git commits. • We should not allow unsigned commits/ packages (at least not with a --allow-unsigned-packages)