@NfNitLoop ("Cody C. #BLM") retweeted:
@bascule ("Tony “Abolish ICE” Arcieri 🦀") wrote:
Of all of the failings of the (Open)PGP/GPG ecosystem, SKS is arguably the worst, both by failing completely from a UX perspective, but also by creating a tool with unclear and counterintuitive security properties that practically no one understands
with quote tweet:
@saleemrash1d ("Saleem Rashid") wrote:
seems like @solarwinds has a vuln disclosure policy that asks you to use their PGP key but, uh, they don't specify a key or fingerprint
d-do they realize that anyone can upload a key to the "secure, global PGP directories" (??????) with any email address
https://www.solarwinds.com/information-security/vulnerability-disclosure-policy