GnuPG 2.1.0 "modern" released
GnuPG 2.1.0 "modern" released
Posted Nov 14, 2014 8:42 UTC (Fri) by dlang (guest, #313)In reply to: GnuPG 2.1.0 "modern" released by dkg
Parent article: GnuPG 2.1.0 "modern" released
if the signature only matters when it's received, why does it need to be cryptographicaly strong? you want to be able to validate the signature years later if it's something worth signing in the first place.
Also, having a standard practice to decrypt all your data and re-encrypt it means exposing data in it's decrypted state much more frequently than you need to. Not a good security recommendation.
