|
|
|
|
|
by lrvick
27 days ago
|
|
> PGP is a bunch of theatre there and distros should use minisign instead. Okay so drop the IETF standard, web of trust, smartcard support, and external key discovery mechanisms to prove the whole keychain was not swapped out with a fake one, and just have everyone generate minisign keys exposed to system memory with no trust link backwards, and then sign things with probably the same algorithms. But then we cannot sign commits or code reviews with minisign because non standard, so i guess use ssh keys for those, and then maintain multiple keychains for each person. Minisign is strictly worse in every way. Your camp will never convince Linux maintainers to switch with this pitch. Many of us actually do verify the web of trust, extensively. I have many Linux maintainers in my own keychain independent from their usage in linux distros. Minisign has no such key distribution and accountability system. |
|
Yes, all of that.