A friend pointed me to the site https://gpg.fail and asked me what I thought of it. At first I didn't think much of it, but on closer inspection it seems there may be some legitimate issues in need of addressing.

See, e.g., https://gpg.fail/detached . I've been able to verify the bottom line claim here, although I haven't verified their diagnosis.

Others, such as https://gpg.fail/noverify, do not seem to be of particular concern. (Point blank: if in 2025 you're using GnuPG at the command line for anything except certificate management, please stop. Parsing GnuPG's command line output is notoriously difficult. Use GPGME with language bindings of your choice.)

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

_______________________________________________
Gnupg-users mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to