zlacker

[return to "Signal Server code on GitHub is up to date again"]
1. jeffo_+En[view] [source] 2021-04-07 16:41:23
>>domano+(OP)
kinda crazy that the signal team doesn't GPG sign their commits.
◧◩
2. hda2+Cq2[view] [source] 2021-04-08 05:02:09
>>jeffo_+En
A example of how irrational hate can make smart people do stupid things, unfortunately.

Certain people on their team don't like the PGP standard despite the fact that it is mature, standardized, and proven to work well for code signing. When questioned about their reasoning, they'd usually deflect and criticize some aspect of PGP that is irrelevant to code signing at all.

In their minds, they believe it is better to rely on git's broken SHA1 fingerprints than to use PGP.

[go to top]