Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I know you aren't actually this stupid, so what exactly is the purpose of your continued trolling? We both know PGP is only covering the distribution portion of the chain. If Theo is owned we're fucked, and if we're owned were fucked (obviously). This is true with PGP, or with what we have now.

So you are saying the openbsd devs should waste time with PGP to solve an issue that is already solved (distribution security). The machine that would be signing the releases is already generating sha256 hashes of them. So as long as you can verify you are getting those hashes from that machine, you are as secure as you can get, PGP or not. And since you can get them over ssh, with a well known public key, you already have everything you need to deal with tampering during distribution. If the machine was compromised and those hashes altered, then it would have been just as much an issue if PGP were in use, since they could alter the binaries before they were signed. You already know all of this, I know you know this, you know you know this, so what are you trying to accomplish by pretending you caught a sudden case of mental retardation?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: