Jakub Jelen wrote: > and sequoia's handling of multiple armored signatures in one file
Bitcoin Core does that. Multiple people sign each release, so security isn't dependent on a single trusted entity. An attacker would have to acquire several people's signing keys. It's a good practice that should be encouraged. I had hoped that the package could be fixed some day to do meaningful signature verification. That will be harder if the ability to handle such files will be lost. Björn Persson
pgpr31hyxM6Ua.pgp
Description: OpenPGP digital signatur
-- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
