Hacker News new | ask | show | jobs
by 0xDEAFBEAD 926 days ago
>When I've found security vulnerabilities in somebody's code, I can't think of a time I ever thought about GPG-signing my notice to them.

It's not authenticity that matters here, it's confidentiality.

1 comments

Basically nobody cares. Vulnerability researchers don't use GPG either.