Re: Official Debian digital 'branding' of debs

>>"Wichert" == Wichert Akkerman <wichert@cs.leidenuniv.nl> writes:

 Wichert> Because just signing everything that is on ftp.debian.org
 Wichert> automatically will create a false sense of security, which
 Wichert> is even worse.
        I agree. Each package should be signed by the developer who
 created it (this is required anyway to get it uploaded). The validity
 of the key is ensured by its presence in an official Debian
 keyring. You know it is official since it is signed by the Master


