Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That a key exist on a random keyserver means nothing. There is a spec that explicitely says "if you want to use my key here it is" and Proton doesn't respect it. what does it mean that you found the key on some third-party domain ? There are 0 safeguards, I don't know what they're going to do with it, there is no obligation from any side. A key in keys.openpgp.org means nothing.


It means someone uploaded it there and verified the address in the identity (or subidentity). A keyserver is exactly for "here's my key, use it".

Don't publish your keys if you don't want them used. It's not that difficult.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: