question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

Please get signing key into PGP WOT

See original GitHub issue

Motivation:

Users need to be able to verify if the release signing key is authentic. Right now that is nearly impossible.

Issue:

The current signing key (D325 87D4 090F E461 CAEE  0FF4 966E 5CB9 CBFA A9BA) is not reachable using the PGP Web Of Trust. It has many signatures, but most keys (17) are not available and the others are isolated (have not been signed by anyone else and could be sock puppets).

Suggested fix:

Exchange key signatures (certifications) with devs who have well connected keys – especially those working on Cardano / Daedalus.

As an interim solution, please post the key fingerprint to various locations to help users gain some vague certainty about the authenticity. Eg: add it to all public presentations, footer of IOHK website, Twitter account, etc. Add it to your README, use it to sign important messages and post those signatures publicly, confirm on this bug that the fingerprint above is correct.

Issue Analytics

  • State:closed
  • Created 4 years ago
  • Reactions:5
  • Comments:5 (2 by maintainers)

github_iconTop GitHub Comments

3reactions
nikolaglumaccommented, Feb 5, 2021

@disassembler please take charge of this one 🙏

0reactions
danielmaincommented, Dec 9, 2021
Read more comments on GitHub >

github_iconTop Results From Across the Web

Getting your PGP key signed by CAcert
The most important thing to note when having your GPG key signed by CAcert is that the name on your key must match...
Read more >
PGP Key Signing
PGP Key Signing. Signing someone's key is saying to the world I have verified the identify of this person to the extent which...
Read more >
What is the PGP Web of Trust Strongset?
Short answer. A strong set key is probably a key signed by a key signed by one of these keys. Meet up with...
Read more >
Validating other keys on your public keyring - GnuPG
In Chapter 1 a procedure was given to validate your correspondents' public keys: a correspondent's key is validated by personally checking his key's...
Read more >
PGP and You - Thoughtbot
Signing a key marks an implicit trust. This means that you have done some amount of work to verify the identity of the...
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found