Jakub Jelen wrote:
> and sequoia's handling of multiple armored signatures in one file

Bitcoin Core does that. Multiple people sign each release, so security
isn't dependent on a single trusted entity. An attacker would have to
acquire several people's signing keys. It's a good practice that should
be encouraged. I had hoped that the package could be fixed some day to
do meaningful signature verification. That will be harder if the
ability to handle such files will be lost.

Björn Persson

Attachment: pgpr31hyxM6Ua.pgp
Description: OpenPGP digital signatur

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to