Hacker News new | ask | show | jobs
by whok 3453 days ago
Agilebits position on PGP signing 1Password.

"Now there certainly are some geek creed we could get from building PGP/GnuPG signatures files, and we might do it. But I'm doubtful that it actually would provide a meaningful improvement in security. On the whole, we try to avoid "security theater" even if it is of the geeky sort"

* They are a bigger target to a watering hole attack than Transmission BT.

* They think authenticating your downloaded is "security theater".

* They are #2 on http://mostvulnerable.com