logoalt Hacker News

maqplast Saturday at 1:50 AM2 repliesview on HN

The biggest issue with PGP/gpg is the difficulty of getting rid of it. If you work on big distros, or know someone who works on big distros, please (start asking them to) add https://github.com/jedisct1/minisign to pre-installed packages to facilitate transition. It's almost a chicken egg problem but the sad thing is, no project wants to swap the signing tool to a better one until everyone can verify the new signatures.


Replies

Avamanderlast Sunday at 11:35 PM

For starters I'd like to see ssh-agent not being replaced with gpg-agent. Those who need it should install it themselves.

singpolyma3last Saturday at 2:58 AM

Note that minisign was also vulnerable in the gpg.fail exposures

show 2 replies