|
|
|
|
|
by zimbatm
4328 days ago
|
|
> Except maybe not: if you happen to do this with GnuPG 2.0.18 -- one version off from the very latest GnuPG -- the client won't actually bother to check the fingerprint of the received key. Even in it's long form, it's relatively easy to generate different keys that have the same fingerprint. |
|
I'd be much more surprised by a full fingerprint match. Wouldn't that imply a SHA-1 collision?
[0] http://www.asheesh.org/note/debian/short-key-ids-are-bad-new...