2 ms·
Well basically, you can't as long as you're loading the web page over an insecure connection. If the .asc is loaded over SSL, then verifying the certificate sho
by misterdata 11y ago
Well basically, you can't as long as you're loading the web page over an insecure connection. If the .asc is loaded over SSL, then verifying the certificate should be sufficient.
- sarciszewski 11y agoEven then, you should also verify it out-of-band (e.g. compare full fingerprints over OTR with someone you trust who has previously saved the same .asc file)
- misterdata 11y agoAgreed, depending on how paranoid you are. The server serving the .asc file over SSL could still be compromised (among other things). Similarly you are unable ascertain that recipient's private key isn't compromised either, or recipient is forced to decrypt, et cetera.