Hacker News new | ask | show | jobs
by FiloSottile 682 days ago
Assuming that implementation never skip verifying the second signature, and compare the signing keys, that should be ok.