[Catalog-sig] User profile: PGP Key ID

Bernhard Seibold bernhard.seibold at gmail.com
Wed Feb 20 19:44:04 CET 2013


Hi!

I noticed that in the user profile, the PGP Key ID is 8 hex digits only. 
This is a bad idea:

http://www.asheesh.org/note/debian/short-key-ids-are-bad-news.html

Honestly I don't know what that Key ID is used for, but it should be 
either fixed or removed.

Have a look at how Launchpad handles PGP keys. It sends you an encrypted 
email with a confirmation link.

https://help.launchpad.net/YourAccount/ImportingYourPGPKey

Regards,
Bernhard


More information about the Catalog-SIG mailing list