On Mon, 2017-04-17 at 17:06 +0100, Nick Kew wrote: > And I need to do some more digging > around that bogus PGP key!
OK, this follows a subject that's been raised @apache before: https://mail-search.apache.org/members/private-arch/members/201606.mbox/%3c1464999260.7490.275.ca...@mimir.webthing.com%3E following which apache's own pages were fixed to stop using 32-bit key IDs. Underlying story is at https://evil32.com/ . I think I shall also blog this story and add my own thoughts. -- Nick Kew