The author seems to forget that a key server makes no validation assurances, it just hosts said key.
There are various other flaws in it and he doesn't seem to understand how the PGP WoT works...
There are various other flaws in it and he doesn't seem to understand how the PGP WoT works...
Fine if you reject web-of-trust style identity verification, but your notion of "web identity verification" is not in any way a good substitute for code signature verification. What if someone compromises your hosted repository? Unless your artifact were already cryptographically signed, no amount of identity verification is going to help you.