Comment on The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026
tribut@infosec.pub 4 days agoCleatext signing (having the signature and data in the same file) is broken in many ways. It is possible to put unsigned data at the top of the file in a way that sha256sum will use it. Watch the 39c3 GPG talk if your interested in the gory details.
The solution is to use detached signatures (checksum.txt and checksum.txt.gpg to verify that). This makes sure that all of checksum.txt is actually covered by the signature.
waltersf@bookwyr.me 4 days ago
cc @modem_down@thebrainbin.org
or, binary signatures, [which I prefer: compressionable], as textfiles are insecure formats.
I prefer a headed, mided, and tailed verification, similar to MPEG keyframing, for constant stream verification.