Whonix Software Signature Verification Documentation Discussion - VirtualBox vs KVM - GPG / signify / codecrypt

Interesting.
No, I don’t think I’ll compile/package codecrypt.

APT uses gpg internally. Therefore we’re bound to a lower security level anyhow, i.e. non-PQCrypto level. If we have gpg / signify signed releases we’re on par, i.e non-PQCrypto level. PQCrypto level signed releases is a nice bonus but wouldn’t really increase security a lot.

Waiting for updated codecrypt version through Debian as usual.
https://packages.debian.org/search?keywords=codecrypt

Related:

1 Like