You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
For something security-sensitive like this, it would be nice to have PGP-signed compressed archives. Even if you just published a PGP and manually uploaded a signed archive one time, that would be great. I would be willing to do this myself, but who am I and how do you know you can trust me and my key?
The text was updated successfully, but these errors were encountered:
Well, the only truly security sensitive bits are the bootstrap seeds (which ideally you would make your own). Everything else was designed to be audited by independent parties. And compressed archives have the problem of having to trust your decompression tools to not tamper with the contents. (which is why mescc-tools-extras bootstraps such tools)
For something security-sensitive like this, it would be nice to have PGP-signed compressed archives. Even if you just published a PGP and manually uploaded a signed archive one time, that would be great. I would be willing to do this myself, but who am I and how do you know you can trust me and my key?
The text was updated successfully, but these errors were encountered: