Oddbean new post about | logout
 Thanks for your time.  When developers make software, they cryptographically sign it to prove that they are the creator.  Just like Nostr.

But the public key for that encryption is on the same big cloud companies (Github) as the software itself.  So people have no way to verify that the developer made it.

One answer is everyone comes on Nostr, but this has things scrolling off the feed and requires each dev to have an account.  Instead, we have laid out all developer public keys on a 2nd new internet called IPFS that is even more difficult than Nostr to backdoor.  So it's a website, instead of a twitter feed for keys.  Hit up our tutorial with Brave Browser:
https://simplifiedprivacy.com/ipfs-brave-browser/ 
 Aah, right. Yes, that makes sense to my simple brain. Thanks for taking the time out to explain, I'll take a look.