Conversation

Uwe Kleine-König

Edited 3 days ago
The PGP Web of Trust in the kernel and SHA-1

PGP is used to sign and (hopefully) also verify pull requests. For a big and relevant part of our community the certifications and cross signatures that are the computational base for the trust in the transferred code changes are already long established.

The problem here is that security is a moving target and the algorithms used back then are not considered secure any more. For example GnuPG (and also other OpenPGP implementations) don’t consider SHA-1 secure any more. See my blog for some effects of that on the kernel Web of Trust.

1
11
7

Uwe Kleine-König

Edited 2 days ago

If you’re attending @embeddedrecipes this year in Nice (May 14-16), register for the PGP keysigning session with @a3f by sending your public key to er2025-keysigning@baylibre.com.

0
2
3