Hacker News new | ask | show | jobs
by click170 3737 days ago
We should really be verifying the fingerprint of the key itself, even if it is served over HTTPS.