Disclaimer: I have only a vague idea about the whole underlying tech but I've also been wondering if there isn't a simpler approach.
Disclaimer: I have only a vague idea about the whole underlying tech but I've also been wondering if there isn't a simpler approach.
The whole point of a blockchain is for people who can’t trust each other. If you have a trusted author, you are correct, you don’t need a blockchain.
> The whole point of a blockchain is for people who can’t trust each other.
I guess that's a very valid point and from my understanding the anonymity baked in is quite unique. And yet, even if I bought say coffee from an independent online market. Probably it's good to have a chain of trust to the seller to know that it's high quality. (Like Amazon reviews)
After all this is what GPG or x509 provide, a chain of trust.
I guess you can't prove who is 'in control' of the repo - the author could have sold the key privately and there's no way to tell if they sold it to multiple new owners.
Kinda like art in the 'real world' - you can 'prove' its the original but no way to tell whos hands its changed through over the years.
With their encrypted keys I presume? A few more steps and you'll have reinvented cryptograpgic ledgers.