Hacker News new | past | comments | ask | show | jobs | submit login

It seems like there's a mistake in the diagram. The "notary → mirror" arrow should be replaced with a "notary → go command" one, because the go command shouldn't trust the mirror when it comes to cryptographic hashes.



I think the mirror can pass through the public signature provided by the notary. That cannot be spoofed if you have a trust chain for the notary to ensure the mirror has not tampered with the module.


The hashes are signed by the notary, go command can get the hashes from anywhere and be able to verified they are signed by the notary.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: