Skip to content

Hard-code trustworthy signers #149

@epiccurious

Description

@epiccurious

Current method for PGP key verification is vulnerable to a sybil attack.

Instead of importing all sigs, hard-code a list of trustworthy devs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    FEATURENew feature or requestSECURITYSecurity and privacy issues

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions