4 ms·
> So your logic could be applied to GPG and argued that it is broken. That's a pretty common claim and has been for a long time. It's not just verification of
by TooBrokeToBeg 8y ago
> So your logic could be applied to GPG and argued that it is broken.
That's a pretty common claim and has been for a long time. It's not just verification of identity, but verification of integrity that the encryption is supposed to enforce. Instead, it throws a warning for one case and will not decrypt for another. The binary client is broken, as a security tool (insofar as it fails to provide the security it claims). If the integrity of the message is compromised, why show a version of the decrypted message at all? There's no guarantee that's correct and has led to this.