Comment on The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026
waltersf@bookwyr.me 1 week agocc @modem_down@thebrainbin.org
or, binary signatures, [which I prefer: compressionable], as textfiles are insecure formats.
I prefer a headed, mided, and tailed verification, similar to MPEG keyframing, for constant stream verification.