Current method for PGP key verification is vulnerable to a sybil attack. Instead of importing all sigs, hard-code a list of trustworthy devs.
Current method for PGP key verification is vulnerable to a sybil attack.
Instead of importing all sigs, hard-code a list of trustworthy devs.