4 ms·
Who decided it was a good idea to publish the signing key on the same domain as the software and not link to any other trustworthy source?
by ecma 12y ago
Who decided it was a good idea to publish the signing key on the same domain as the software and not link to any other trustworthy source?
- handsomeransoms 12y agoIt's also on the keyservers: http://pgp.mit.edu/pks/lookup?search=0xEBA34B1C&op=index http://pgp.mit.edu/pks/lookup?search=0xEBA34B1C&op=index
- hngiszmo 12y agoit's most likely important to check the signatures of the key. But yeah, this is one aspect where I always look confused about the security theater. You need a closed chain of trust (which can include a trusted root CA). Else it's all worthless. Two servers are almost as easy to MITM-attack as one if you are the oppressive government that has back doors to the common pre-installed ssl certs.