4 ms·
That's still a problem. Having an incorrect breakable public key posted on the server. Why doesn't the key server scan for this and reject them?
by emmab 10y ago
That's still a problem. Having an incorrect breakable public key posted on the server.
Why doesn't the key server scan for this and reject them?
- asciilifeform 10y agoAsk the SKS folks why not?
- cyphar 10y agoKey severs don't implement any non-trivial verification. Presumably they have some reason for doing so (apart from laziness). I'd ask them why they don't implement it.