Comment on The gpg.fail aftermath: On responsible disclosure, GPG, and the state of security in 2026
ChunderBustickles@piefed.nz 5 days ago
Please bear with my dumb ass. if validating a certificate / signature is risking an RCE, does that essentially make this a planet-wide potential supply chain hack (wherever gnupg is used, at least?)
ChunderBustickles@piefed.nz 5 days ago
Follow up: I suppose the verification could be done in a container?