all messages for Guix-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
* Suggest another way of importing GNU Guix GPG key
@ 2019-06-29 21:11 dftxbs3e
  2019-06-29 21:40 ` Alex Vong
  0 siblings, 1 reply; 10+ messages in thread
From: dftxbs3e @ 2019-06-29 21:11 UTC (permalink / raw)
  To: guix-devel

Hello,

SKS keyservers are currently under attack 
(https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f) - 
the attack can cause a GPG client to freeze completely and mess the GPG 
installation completely.

I suggest GNU Guix proposes another way of importing the GPG keys so 
that users will not suffer from this problem.

There's another, newer, keyserver, proposed in this gist, that is run by 
new software that doesnt suffer from this attack. See: 
https://keys.openpgp.org/about/news#2019-06-12-launch

However, that keyserver is not replicated. You could either use that one 
or simply offer a download of the key over TLS with verification against 
installed CAs, as secure as this can get.

Regards

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2019-07-18  8:59 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-06-29 21:11 Suggest another way of importing GNU Guix GPG key dftxbs3e
2019-06-29 21:40 ` Alex Vong
2019-06-29 21:57   ` Christopher Lemmer Webber
2019-06-30  9:44   ` Giovanni Biscuolo
2019-07-02 15:54     ` Leo Famulari
2019-07-03 18:13       ` Leo Famulari
2019-07-13 18:29         ` Leo Famulari
2019-07-17 20:40           ` dftxbs3e
2019-07-18  8:03             ` Ricardo Wurmus
2019-07-18  8:58               ` Julien Lepiller

Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/guix.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.