logoalt Hacker News

singpolyma3last Saturday at 2:58 AM2 repliesview on HN

Note that minisign was also vulnerable in the gpg.fail exposures


Replies

woodruffwlast Saturday at 3:01 AM

Yes, but not nearly to the same extent. The GPG vulns are staggering in comparison.

maqplast Saturday at 5:34 AM

All software has bugs. But having a small purpose-built program do one thing well is much smaller attack surface. The Unix philosophy also makes a pretty good security argument.