Provide signed downloads or downloads over HTTPS #98
Loading…
Reference in New Issue
There is no content yet.
Delete Branch "%!s(<nil>)"
Deleting a branch is permanent. Although the deleted branch may exist for a short time before cleaning up, in most cases it CANNOT be undone. Continue?
Or both!
Would BSD signify(1) signatures be acceptable?
PGP signatures would be preferable. What's the advantage of signify?
The cryptographic primitives provided by OpenPGP are outdated, signify on the other hand uses Ed25519. On top of that, generally, maintaining a PGP key is a pain in the ass (pointless web of trust, key expiry, ASN.1 object identifiers, blah blah blah). Signify on the other hand is similar to maintaining a bitcoin wallet.
I'm not convinced that the primitives have practically exploitable flaws at the moment, and signify deployment is pretty lacking. Could you consider publishing both with a long term plan for switching entirely to signify?
Thanks!