Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It’s so easy to use insecurely that I will argue that employees setting up PGP keys and then potentially trying to use them does weaken the company’s security posture.


I agree it is easy for people to shoot themselves in the foot with many historcal PGP tools, which is exactly why we made keyfork.

It generates modern ECC PGP keychains with best practices in one shot, with multiple reasonably secure user friendly paper or smartcard, backup solutions.

You will really know what you are doing to force keyfork to generate an unsafe keychain. Especially if you use it on AirgapOS, which ships with it.


Care to elaborate on this? How come using PGP insecurely is somehow more insecure than not using it at all? And what do you exactly mean by using it insecurely? Care to give me an example of this insecure use of PGP?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: