|
|
Log in / Subscribe / Register

Disconnect between the developers and the users

Disconnect between the developers and the users

Posted Jan 22, 2026 9:12 UTC (Thu) by dottedmag (subscriber, #18590)
Parent article: Responses to gpg.fail

> the only serious bug from their list

This raises a question: who is the target audience for the gpg CLI tool?

Serious security researchers? Then why the project's website does not have a huge "Do not even attempt to use this project yourself" banner, and why gpg signatures are used to verify downloads, why gpg CLI usage is given as "how to check the downloads" documentation?

Non-security gurus? Then these "non-serious bugs" are actually very, very serious.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds