Yet another "GPG bug" that isn't *really* a GPG bug... The app let's you specify a status fd and people pass in "2" and mix it up with stderr? Does *anyone* downstream in the PGP ecosystem understand basic security hygiene? https://neopg.io/blog/gpg-signature-spoof/#proof-of-concept-ii-signature-and-encryption-spoof-enigmail …
-
-
I think there are way too many abstraction layers sometimes, which involves different developers. A proactive solution would be security checks with all layers in place during development, the way things are now this usually doesn't happen until exploit/spoof is found.
-
Archaic interface. GPG thinks it isn’t their problem to cater to tool devs or check their work. And tool devs pretty routinely get it wrong.pic.twitter.com/jDqFEYria2
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.