Please get signing key into PGP WOT
See original GitHub issueMotivation:
Users need to be able to verify if the release signing key is authentic. Right now that is nearly impossible.
Issue:
The current signing key (D325 87D4 090F E461 CAEE 0FF4 966E 5CB9 CBFA A9BA
) is not reachable using the PGP Web Of Trust. It has many signatures, but most keys (17) are not available and the others are isolated (have not been signed by anyone else and could be sock puppets).
Suggested fix:
Exchange key signatures (certifications) with devs who have well connected keys – especially those working on Cardano / Daedalus.
As an interim solution, please post the key fingerprint to various locations to help users gain some vague certainty about the authenticity. Eg: add it to all public presentations, footer of IOHK website, Twitter account, etc. Add it to your README, use it to sign important messages and post those signatures publicly, confirm on this bug that the fingerprint above is correct.
Issue Analytics
- State:
- Created 4 years ago
- Reactions:5
- Comments:5 (2 by maintainers)
Top GitHub Comments
@disassembler please take charge of this one 🙏
We provide instructions for this here: https://daedaluswallet.io/en/download/#modal=download_pgp_instructions_darwin