|
|
Log in / Subscribe / Register

communication

communication

Posted Jan 22, 2026 4:16 UTC (Thu) by wtarreau (subscriber, #51152)
In reply to: communication by Phantom_Hoover
Parent article: Responses to gpg.fail

I totally agree with you. All these domain names, logos etc are only there to maximize the buzz that creates self-promotion for the security teams who find bugs. But they're not heroes, just code reviewers who find complicated bugs, and should be more respectful for the ones doing all the fixing work, very often in code they didn't write themselves, but only inherited from previous developers, or accepted from external contributions.

There can be plenty of reasons to criticize the gpg tool for being overly complicated to use, almost unusable in scripts not running in a tty, or for spawning an agent daemon even when you don't want one in recent versions, but this might just not be the right tool for certain tasks. And in any case it doesn't deserve insults like filing a domain such as this one, that the project maintainers will have no handle on regardless of their efforts to fix everything mentioned there.

When you think about it, for many OSS developers, the project they work on is an important part of their resume. Here, you apply for a job, proudly arboring 10 years in gpg, and the employer says "ah, yes, any responsibility in gpg.fail?". It's just not fair to force these people to justify themselves when everyone has been relying on their work, so I hope this domain will not be renewed once it expires.


to post comments

communication

Posted Jan 25, 2026 17:04 UTC (Sun) by SLi (subscriber, #53131) [Link]

> There can be plenty of reasons to criticize the gpg tool for being overly complicated to use, almost unusable in scripts not running in a tty, or for spawning an agent daemon even when you don't want one in recent versions, but this might just not be the right tool for certain tasks.

Would you allow that there might some some responsibility for a developer of a major security tool that gains significant "not right tool" uses to be more vocal about it not being the right tool?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds