3 ms·
> adoption for tools like PGP never picked up nit: Every competent developer I know uses PGP on a daily basis, for signing and validating commits. The responsi
by thinkmassive 3y ago
> adoption for tools like PGP never picked up
nit: Every competent developer I know uses PGP on a daily basis, for signing and validating commits. The responsible ones also use it to validate security-critical software is coming from the expected source. I do agree though, that the original use case of encrypted email is largely dead.
- verandaguy 3y agoGood point, though in Git's case there's the benefit of: - Users are at least somewhat technically minded - The ecosystem built around Git generally has good automated tooling for verifying signed commits (Gitlab and Github in particular surface that information pretty well) With security-critical software, specialists take on the burden of knowing how to use it as part of being in that field. Email sadly has none of those, and the one client I've used with a "normal"-user-friendly GPG interface (Nylas N1) is now a subscription service with limited adoption. Enigmail was better than the CLI, but still not super intuitive for the average person.