Earlier quoted context omitted.
It's naive to believe that any form of physical presence means someone isn't going to do something nefarious in the eyes of the project. This problem can only be solved by more skilled eyes on the projects that we rely on. How do we get there? shrug.gif . Anything less is trying to find a cheap and ineffective shortcut in this trust model.
> It's naive to believe that any form of physical presence means someone isn't going to do something nefarious in the eyes of the project. It's not the only thing, but it is something. There's a lot of social engineering that went into the xz backdoor[0]. This started years ago; Jia Tan was posting in projects and suddenly someone appeared to pressure projects to accept their code. Who's Jia Tan? Who's Jigar Kumar, t…
This is assuming maintainers even care/want to go.
> has an actual face, and is on security camera footage at multiple hotels and airports
The same footage that'll get wiped a few weeks after the conference ends, and quickly becomes not useful.
This is wonderful posturing in the name of security theater but doesn't solve anything.