

While AI obviously is not perfect and is flawed in many ways, having AI sift through the torrent of comments and then flag problematic submissions for human review is likely going to be extremely effective with minimal false positives. Though I do say this as a person whose Reddit account is currently banned for 3 days for “inciting violence” because of a knife-based joke.








I’m guessing what you’re suggesting is that Google’s proposal is the same as requiring all packages be signed and accompanied by an Extended Validation or Oragnisation Validation X.509 certificate.
While that would technically work, the problem with using the existing PKI is that it’s still very expensive to get EV/OV certificates. And the most common of these certs (those for TLS purposes) will soon only last 47 days which is, to put it mildly, would be a pain in the ass to use for package-signing.