Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

fwiw keys.pub has not had a commit to any of their GitHub repos since July 9 of this year


No, within the last month.

One thing is that I don't see anything about auditing for Keyoxide, but Keys is up-front with a warning.


Keyoxide doesn't use any cryptography, everything is handled by identities in PGP. I doubt it needs any auditing.

The only reasonable attack vector I can see is hijacking the website (or proxy server) to return different keys or show something is verified when it's actually not.


I haven't checked quite what Keyoxide is doing, but I'm not sure cryptography is the only thing worth auditing for security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: