Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <0f885422-9937-438c-85cd-4f6850ee5b72@gmail.com>
Date: Tue, 30 Dec 2025 23:44:05 -0600
From: Jacob Bachmeyer <jcb62281@...il.com>
To: oss-security@...ts.openwall.com, Peter Gutmann <pgut001@...auckland.ac.nz>
Subject: Re: Many vulnerabilities in GnuPG

On 12/29/25 18:57, Peter Gutmann wrote:
> [...]
>
> A solution for mission-critical use like authenticating downloaded binaries
> would be to do two things:
>
> 1. Create an app that does just that and nothing else: Here is a blob of data,
> here is a detached signature, is it valid for the data?

Does using gpgv(1) with detached signatures fit this bill?

I am unsure what having a separate tool dedicated for verifying 
signatures using trusted keyrings says about the overall system...


-- Jacob


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.