Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Looks good.

gpg: Signature made Mon Jul 13 08:44:56 2009 PDT using DSA key ID 7D6F806C gpg: Good signature from "rsync.net <info@rsync.net>"



You realize that unless you have a trust path via keys that you've signed (preferably by meeting the people holding them) that that verification isn't verifying much, right?

It's pretty easy to create a key that has that key id (since it's only the last few hex digits of the full 40 digit fingerprint) and the user id is freeform.

If you don't believe it's easy to pick your own key id, check the keyservers for the number of keys with DEADBEEF as their key id ;)


yes. And if I were a customer of theirs I'd work to obtain a more trusted copy of their key. But, FYI, I've had this copy of their key in my keyring for several years, I didn't just pull it off their website today.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: