http://lpoaj76nfopd5lpinbskyqtroppamrzhhay3g4vvjm75st6ger34lbyd.onion/posts/2022/09/administration-thoughts.html
Secondly, what's the point in doing this even? The point's distrusting the way current web PKI's done (i.e. via DNS(SEC) n CAs). But, 'f the system in general's compromised, we got other issues, like our applications themselves perhaps being malicious, as they're usually fetched from HTTPS sites, w not much other verification done by the package maintainers.