> You mean running untrusted code from the Web? Nigel said it would be possible to secure it a bit using GPG keys. Maybe this kind of signing should be made a requirement.
Well, should signing be necessary and/or sufficient, and who makes that decision?